Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2020-11072 Vulnerability in npm package slp-validate
CVE-2019-10742 Vulnerability in npm package axios
CVE-2023-37908 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-xml
CVE-2022-36944 Vulnerability in maven package org.scala-lang:scala-library
CVE-2023-37947 Vulnerability in maven package org.openshift.jenkins:openshift-login