Description
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Remediation
References
https://hackerone.com/reports/703412
Related Vulnerabilities
CVE-2023-3815 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2015-8860 Vulnerability in maven package org.webjars:tar
CVE-2015-8851 Vulnerability in maven package org.webjars:node-uuid
CVE-2020-28481 Vulnerability in maven package org.webjars.npm:socket.io
CVE-2019-16869 Vulnerability in maven package org.jboss.netty:netty