Описание
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.
Ссылки
- Broken LinkThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Broken LinkThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.1 (исключая)
cpe:2.3:a:madge_project:madge:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 70%
0.00625
Низкий
8.6 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
EPSS
Процентиль: 70%
0.00625
Низкий
8.6 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89