Lucene search

K
osvGoogleOSV:GHSA-2M8V-572M-FF2V
HistoryFeb 16, 2021 - 4:51 p.m.

Command Injection Vulnerability

2021-02-1616:51:04
Google
osv.dev
20

0.973 High

EPSS

Percentile

99.9%

Impact

command injection vulnerability

Patches

Problem was fixed with a parameter check. Please upgrade to version >= 5.3.1

Workarounds

If you cannot upgrade, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() … do only allow strings, reject any arrays. String sanitation works as expected.

CPENameOperatorVersion
systeminformationlt5.3.1