Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2022-41937 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui
CVE-2022-28367 Vulnerability in maven package org.owasp:antisamy
CVE-2019-17563 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-39133 Vulnerability in maven package org.rundeck:rundeck
CVE-2021-32808 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4