CVE-2022-25906

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:is-http2_project:is-http2:-:*:*:*:*:node.js:*:*

Information

Published : 2023-01-31 21:15

Updated : 2023-02-08 07:38


NVD link : CVE-2022-25906

Mitre link : CVE-2022-25906


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

is-http2_project

  • is-http2