Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2023-22491 Vulnerability in npm package gatsby-transformer-remark
CVE-2018-13797 Vulnerability in maven package org.webjars.npm:macaddress
CVE-2022-36045 Vulnerability in npm package nodebb
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2020-8141 Vulnerability in maven package org.webjars.bowergithub.olado:dot