Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2019-5427 Vulnerability in maven package com.mchange:c3p0
CVE-2020-13822 Vulnerability in npm package elliptic
CVE-2020-28435 Vulnerability in npm package ffmpeg-sdk
CVE-2020-11113 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-38369 Vulnerability in maven package org.apache.iotdb:iotdb-server