Description
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://nodesecurity.io/advisories/codem-transcode_command_injection
Related Vulnerabilities
CVE-2020-2220 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2019-10315 Vulnerability in maven package org.jenkins-ci.plugins:github-oauth
CVE-2019-3868 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2020-2110 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2019-1003056 Vulnerability in maven package org.jenkins-ci.plugins:websphere-deployer