Description
OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.
Remediation
References
https://github.com/kujirahand/nadesiko3/issues/1325
https://github.com/kujirahand/nadesiko3/issues/1347
https://jvn.jp/en/jp/JVN56968681/index.html
Related Vulnerabilities
CVE-2021-31405 Vulnerability in maven package com.vaadin:vaadin-text-field-flow
CVE-2024-4367 Vulnerability in npm package pdfjs-dist
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2022-29078 Vulnerability in maven package org.webjars.npm:ejs
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core