GHSA-2275-rpf5-xv8h

Source
https://github.com/advisories/GHSA-2275-rpf5-xv8h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-2275-rpf5-xv8h/GHSA-2275-rpf5-xv8h.json
Aliases
  • CVE-2022-25906
Published
2023-02-01T06:30:30Z
Modified
2023-11-08T04:08:51.701195Z
Details

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

References

Affected packages

npm / is-http2

Package

Name
is-http2

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
1.2.0