ZeroHour

CVE-2022-25962

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

Vendors
vagrant.js project
Products
vagrant.js
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.