CVE-2021-42139

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-42139
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-42139.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-42139
Published
2021-10-11T05:15:06Z
Modified
2025-01-08T08:22:28.089375Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.

References

Affected packages

Git / github.com/denoland/deno_std

Affected ranges

Type
GIT
Repo
https://github.com/denoland/deno_std
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.100.0
0.101.0
0.102.0
0.103.0
0.104.0
0.105.0
0.106.0
0.85.0
0.86.0
0.87.0
0.88.0
0.89.0
0.90.0
0.91.0
0.92.0
0.93.0
0.94.0
0.95.0
0.96.0
0.97.0
0.98.0
0.99.0

Other

20190516
20190520

v0.*

v0.1.11
v0.1.12
v0.10.0
v0.11.0
v0.12.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.2.0
v0.2.1
v0.2.10
v0.2.11
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9
v0.20.0
v0.3.0
v0.3.1
v0.3.10
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.8
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0