Junglewise Threat Intelligence

CVE-2022-25350: puppet-facter command injection in getFact

CVE-2022-25350 · Severity: low · CVSS 3.1 · Published 2023-01-26

Vendors: npm.

Executive brief

puppet-facter is a Node.js library that retrieves system fact data by executing the facter system utility. The getFact function fails to properly sanitize user-supplied input before passing it to shell commands, allowing an attacker to inject arbitrary shell commands and execute them with the privileges of the application.

Technical details

The vulnerability is a command injection flaw (CWE-77, CWE-78) in the getFact function. The root cause is improper input sanitization of the factName parameter, which is directly concatenated into a shell command string passed to child_process.exec(). An attacker who can control the factName argument can inject shell metacharacters and arbitrary commands. The attack requires local or authenticated access to the application that uses puppet-facter. Successful exploitation allows arbitrary command execution with the privileges of the Node.js process. All versions up to and including 0.0.2 are affected; no patch availability is indicated in the advisory.

Affected products

  • npm puppet-facter 0.0.2 and earlier

Timeline

  • 2023-01-26: disclosed
  • 2023-01-27: advisory: GitHub security advisory reviewed

References