Description
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://nodesecurity.io/advisories/codem-transcode_command_injection
Related Vulnerabilities
CVE-2023-27848 Vulnerability in npm package broccoli-compass
CVE-2023-26512 Vulnerability in maven package org.apache.eventmesh:eventmesh-connector-rabbitmq
CVE-2021-23568 Vulnerability in npm package extend2
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2022-29219 Vulnerability in npm package @chainsafe/lodestar