CVE-2020-28494
Summary
| CVE | CVE-2020-28494 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-02 11:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option shell set to true and because the type parameter is not properly sanitized. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Command Injection in total.js | Snyk | MISC | snyk.io | Exploit, Patch, Third Party Advisory |
| Fixed "Command Injection" in `image.stream()` - thank to Sam Sanoop. · totaljs/framework@6192491 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Alessio Dellalibera
Legacy QID Mappings
- 981924 Nodejs (npm) Security Update for total.js (GHSA-4449-hg37-77v8)