{"cvss":7.1,"datePublished":"2022-01-18","dateUpdated":"2022-01-18","description":"In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.","dueDate":"2022-02-01","id":"CVE-2021-21315","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-21315","product":"System Information Library for Node.JS","requiredAction":"Apply updates per vendor instructions.","severity":"HIGH","source":"cisa_known_exploited","title":"System Information Library for Node.JS Command Injection","vendor":"Npm package"}