Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2018-20433 Vulnerability in maven package c3p0:c3p0
CVE-2018-11647 Vulnerability in npm package oauth2orize-fprm
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:openejb-client
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wms
CVE-2021-29442 Vulnerability in maven package com.alibaba.nacos:nacos-common