PT-2018-1369 · Node.Js · Pdf-Image

Defmax

·

Publicado

2018-05-30

·

Atualizado

2020-09-01

·

CVE-2018-3757

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pdf-image versions prior to 2.0.0
Description The issue is related to the lack of neutralization of special elements in input data for the GetInfoCommand function in the pdf-image tool for Node.js. This can be exploited by a remote attacker to execute arbitrary code using a specially crafted request. The vulnerability exists due to an unescaped string parameter, and it is exploitable if the attacker has control over the pdfFilePath variable passed into pdf-image.
Recommendations Update to version 2.0.0 or later. As a temporary workaround, consider restricting access to the pdf-image tool to minimize the risk of exploitation, especially for the pdfFilePath variable. Avoid using unvalidated input for the pdfFilePath variable in the affected API endpoint until the issue is resolved.

Exploit

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00912
CVE-2018-3757
GHSA-5GWH-G79J-VH4Q

Produtos afetados

Pdf-Image