Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2018-3722 Vulnerability in maven package org.webjars.npm:merge-deep
CVE-2021-41183 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2021-24033 Vulnerability in maven package org.webjars.npm:react-dev-utils
CVE-2020-28479 Vulnerability in maven package org.webjars.bower:jointjs