CVE-2019-10788
Summary
| CVE | CVE-2019-10788 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 21:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Dnt |
Im-metadata |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| fix: check path argument before processing (#10) · Turistforeningen/node-im-metadata@ea15ddd · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Command Injection in im-metadata | Snyk |
MISC |
snyk.io |
Exploit, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982792 Nodejs (npm) Security Update for im-metadata (GHSA-qfxv-qqvg-24pg)