A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| @zowe/imperative(npm) | 5.0.0 | 5.7.1 | N/A |
| @zowe/imperative(npm) | 0 | 4.18.10 | N/A |
CVSS Metrics