DEBIAN-CVE-2021-21315

Source
https://security-tracker.debian.org/tracker/CVE-2021-21315
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-21315.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2021-21315
Upstream
Withdrawn
2026-06-01T20:00:40Z
Published
2021-02-16T17:15:13Z
Modified
2026-06-01T20:00:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

References

Affected packages

Debian:14 / node-systeminformation

Package

Name
node-systeminformation
Purl
pkg:deb/debian/node-systeminformation?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.31.6-1
5.31.6-2
5.31.6-3
5.31.6-4
5.31.7-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-21315.json"