Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2022-45394 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2020-28461 Vulnerability in npm package js-ini
CVE-2021-21252 Vulnerability in maven package org.webjars.bower:jquery-validation