CVE-2021-23422
Summary
| CVE | CVE-2021-23422 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-16 08:15:00 UTC |
| Updated | 2021-08-23 19:02:00 UTC |
| Description | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Arbitrary Code Injection in bikeshed | Snyk |
CONFIRM |
snyk.io |
|
| Prevent escaping the source doc's folder, or running arbitrary code, … · tabatkins/bikeshed@b2f668f · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: apple502j
Legacy QID Mappings
- 981429 Python (pip) Security Update for bikeshed (GHSA-87cj-px37-rc3x)