PT-2022-8889 · Unknown · Node-Latex-Pdf

Published

2022-08-02

·

Updated

2022-08-08

·

CVE-2020-28433

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions node-latex-pdf versions all
Description A command injection issue affects the package. This allows for potential exploitation. The estimated number of potentially affected devices is not provided.
Recommendations For all versions, consider restricting the use of the package until a fix is available. As a temporary workaround, avoid using the package in environments where command injection could be exploited. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-28433
GHSA-32FW-9WQ8-9X9C

Affected Products

Node-Latex-Pdf