Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement
CVE-2021-37694 Vulnerability in npm package @asyncapi/java-spring-cloud-stream-template
CVE-2014-7191 Vulnerability in maven package org.webjars:qs
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore