CVE-2021-26276
27.01.2021, 20:15
scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted dataEnginsight
Vendor | Product | Version |
---|---|---|
godaddy | node-config-shield | 𝑥 < 0.2.3 |
𝑥
= Vulnerable software versions
References