OSV 1.4.0 · github-reviewed · 修改于 2023-09-07 02:31
发布时间
2021-05-08 00:20
GitHub 审查时间
2021-05-05 03:02
NVD 发布时间
2020-03-16 06:15
源文件
advisories/github-reviewed/2021/05/GHSA-fmf5-j5j9-99pp/GHSA-fmf5-j5j9-99pp.json
pulverizr through 0.7.0 allows execution of arbitrary commands. Within lib/job.js, the variable filename can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.