Description
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Remediation
References
https://hackerone.com/reports/703412
Related Vulnerabilities
CVE-2021-23353 Vulnerability in maven package org.webjars.bower:jspdf
CVE-2020-35451 Vulnerability in maven package org.apache.oozie:oozie-tools
CVE-2022-41965 Vulnerability in maven package org.opencastproject:opencast-engage-paella-player
CVE-2016-10534 Vulnerability in npm package electron-packager
CVE-2018-25079 Vulnerability in maven package org.webjars.npm:is-url