Description
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4811/
https://github.com/stoqey/gnuplot/blob/cd76060a15f58348baeef1c5fd867ce856515949/src/index.ts#L211-L217
Related Vulnerabilities
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-24998 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2022-25860 Vulnerability in maven package org.webjars.npm:simple-git
CVE-2022-37734 Vulnerability in maven package com.graphql-java:graphql-java
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core