Description
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1188 | Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input. |
Github GHSA |
GHSA-rv7p-mmwq-x674 | Improper Input Validation and Code Injection in pdf-image |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/781664 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:48:25.599Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8132
No data.
Status : Modified
Published: 2020-02-28T20:15:11.693
Modified: 2024-11-21T05:38:21.363
Link: CVE-2020-8132
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA