Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7w2-cg47-7v79

Опубликовано: 29 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

EPSS

Процентиль: 79%
0.01301
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

EPSS

Процентиль: 79%
0.01301
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77