CVE-2022-29622
Summary
| CVE | CVE-2022-29622 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-16 14:15:00 UTC |
| Updated | 2023-11-07 03:46:00 UTC |
| Description | An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Filename filtering is inappropriate · Issue #862 · node-formidable/formidable · GitHub |
MISC |
github.com |
|
| Please Wait... | Cloudflare |
MISC |
medium.com |
|
| Vulnerability CVE-2022-29622 is reported by Whitesource · Issue #856 · node-formidable/formidable · GitHub |
MISC |
github.com |
|
| Formidable Vulnerability - YouTube |
MISC |
www.youtube.com |
|
| Is CyberSecurity the Next Supply Chain Vulnerability? - Zsolt Imre - Medium |
|
medium.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184631 Debian Security Update for node-formidable (CVE-2022-29622)