Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-29622

Опубликовано: 16 мая 2022
Источник: debian
EPSS Средний

Описание

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-formidablefixed3.2.4+20220519git81dd350+~cs4.0.9-1package

Примечания

  • https://github.com/node-formidable/formidable/issues/856

  • https://medium.com/@zsolt.imre/cve-2022-29622-in-vulnerability-analysis-5cf783c3721

EPSS

Процентиль: 96%
0.24201
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVSS3: 9.8
nvd
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVSS3: 9.8
github
больше 3 лет назад

Formidable arbitrary file upload

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость библиотеки Formidable, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.24201
Средний