Description
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Remediation
References
https://hackerone.com/reports/703412
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package com.loopeer.android:bootstrap
CVE-2019-10295 Vulnerability in maven package org.jenkins-ci.plugins:crittercism-dsym
CVE-2023-30331 Vulnerability in maven package com.ibeetl:beetl
CVE-2019-1003044 Vulnerability in maven package org.jenkins-ci.plugins:slack
CVE-2019-3580 Vulnerability in maven package org.openrefine:openrefine