CVE-2022-25906

7.4HIGH

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

Опубликовано: 2/1/2023Обновлено: 3/26/2025

Описание

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

ИИ-АнализНа базе ИИ

Затронутые продукты

is-http2_projectis-http2
-

Ссылки