CVE-2021-34078
Published
CVSS v3
8.8
HIGH
CVSS v2
9.3
HIGH
Affected
1
PROJECT
Description
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
Checks that installed NPM modules are the latest currently available version.