Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cp3-66vr-3r4c

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Formidable arbitrary file upload

Withdrawn: This advisory was improperly assigned.

An arbitrary file upload vulnerability in formidable v3.2.4 allows attackers to execute arbitrary code via a crafted filename.

Пакеты

Наименование

formidable

npm
Затронутые версииВерсия исправления

< 3.2.4

3.2.4

EPSS

Процентиль: 96%
0.24201
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVSS3: 9.8
nvd
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

CVSS3: 9.8
debian
больше 3 лет назад

An arbitrary file upload vulnerability in formidable v3.1.4 allows att ...

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость библиотеки Formidable, связанная с неограниченной загрузкой файлов опасного типа, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.24201
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434