Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4776
Related Vulnerabilities
CVE-2020-24616 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-47105 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2018-3752 Vulnerability in npm package merge-options
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat:tomcat-coyote