Description
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://nodesecurity.io/advisories/codem-transcode_command_injection
Related Vulnerabilities
CVE-2022-21213 Vulnerability in maven package org.webjars:mout
CVE-2019-1003026 Vulnerability in maven package org.jenkins-ci.plugins:mattermost
CVE-2019-1003057 Vulnerability in maven package org.jenkins-ci.plugins:bitbucket-approve
CVE-2019-10775 Vulnerability in npm package ecstatic
CVE-2019-10335 Vulnerability in maven package org.jenkins-ci.plugins:electricflow