PT-2018-1369 · Node.Js · Pdf-Image
Defmax
·
Publicado
2018-05-30
·
Atualizado
2020-09-01
·
CVE-2018-3757
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
pdf-image versions prior to 2.0.0
Description
The issue is related to the lack of neutralization of special elements in input data for the GetInfoCommand function in the pdf-image tool for Node.js. This can be exploited by a remote attacker to execute arbitrary code using a specially crafted request. The vulnerability exists due to an unescaped string parameter, and it is exploitable if the attacker has control over the
pdfFilePath variable passed into pdf-image.Recommendations
Update to version 2.0.0 or later. As a temporary workaround, consider restricting access to the
pdf-image tool to minimize the risk of exploitation, especially for the pdfFilePath variable. Avoid using unvalidated input for the pdfFilePath variable in the affected API endpoint until the issue is resolved.Exploit
Correção
OS Command Injection
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pdf-Image