CVE-2024-27980

Aliases:CGA-2mp3-c5fh-w687CGA-6mpf-c3r4-gc7qCGA-8rj5-ffvv-3h5jCGA-g49p-hgvf-r9xgCGA-hf4m-22rq-3qg8CGA-rhcc-5jvp-4x7cCGA-v72c-4qcg-v779CGA-wj9m-mvcp-742j
Deferred
Published: 09 Jan 2025, 00:33
Last modified:30 Apr 2025, 22:25

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.0 (cve.org)
EPSS Score
1.41% LOW
1% probability +1.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jan 2025, 00:33
Published
Vulnerability first disclosed
30 Apr 2025, 22:25
Last Modified
Vulnerability information updated

Description

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 1.41% Percentile: 71%

Techniques & Countermeasures

  • CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')

    The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Affected Systems

  • chainguardnodejs-16

    < 16.20.2-r16

  • chainguardnodejs-18

    < 18.20.2-r0

  • chainguardnodejs-20

    < 20.12.2-r0

  • chainguardnodejs-21

    < 21.7.3-r0

  • wolfinodejs-16

    < 16.20.2-r16

  • wolfinodejs-18

    < 18.20.2-r0

  • wolfinodejs-20

    < 20.12.2-r0

  • wolfinodejs-21

    < 21.7.3-r0

  • nodejsnode

    ≥ 4.0, < 4.* | ≥ 5.0, < 5.* | ≥ 6.0, < 6.* | ≥ 7.0, < 7.* | ≥ 8.0, < 8.* | ≥ 9.0, < 9.* | ≥ 10.0, < 10.* | ≥ 11.0, < 11.* | ≥ 12.0, < 12.* | ≥ 13.0, < 13.* | ≥ 14.0, < 14.* | ≥ 15.0, < 15.* | ≥ 16.0, < 16.* | ≥ 17.0, < 17.* | ≥ 18.0, < 18.20.2 | ≥ 19.0, < 19.* | ≥ 20.0, < 20.12.2 | ≥ 21.0, < 21.7.3

References (5)