PT-2022-8889 · Unknown · Node-Latex-Pdf
Published
2022-08-02
·
Updated
2022-08-08
·
CVE-2020-28433
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
node-latex-pdf versions all
Description
A command injection issue affects the package. This allows for potential exploitation. The estimated number of potentially affected devices is not provided.
Recommendations
For all versions, consider restricting the use of the package until a fix is available. As a temporary workaround, avoid using the package in environments where command injection could be exploited. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Latex-Pdf