Description
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://nodesecurity.io/advisories/codem-transcode_command_injection
Related Vulnerabilities
CVE-2021-23413 Vulnerability in npm package jszip
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2020-7662 Vulnerability in npm package websocket-extensions
CVE-2020-28498 Vulnerability in maven package org.webjars.npm:elliptic
CVE-2019-12399 Vulnerability in maven package org.apache.kafka:kafka