Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2021-29451 Vulnerability in maven package com.manydesigns:portofino-core
CVE-2022-25916 Vulnerability in npm package mt7688-wiscan
CVE-2022-28153 Vulnerability in maven package org.jvnet.hudson.plugins:sitemonitor
CVE-2021-41184 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2020-7751 Vulnerability in maven package org.webjars.npm:pathval