Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2022-0436 Vulnerability in maven package org.webjars.npm:grunt
CVE-2020-29204 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2020-7605 Vulnerability in npm package gulp-tape
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:sbt