Description
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
Remediation
References
https://hackerone.com/reports/703412
Related Vulnerabilities
CVE-2017-3150 Vulnerability in maven package org.apache.atlas:apache-atlas
CVE-2016-10546 Vulnerability in npm package pouchdb
CVE-2017-3586 Vulnerability in maven package mysql:mysql-connector-java
CVE-2019-15782 Vulnerability in npm package webtorrent
CVE-2016-10542 Vulnerability in maven package org.webjars.npm:ws