QID 980707
QID 980707: Nodejs (npm) Security Update for gm (GHSA-pjh3-jv7w-9jpr)
Versions of `gm` prior to 1.21.1 are affected by a command injection vulnerability. The vulnerability is triggered when user input is passed into `gm.compare()`, which fails to sanitize input correctly before calling the graphics magic binary.
## Recommendation
Update to version 1.21.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pjh3-jv7w-9jpr for updates pertaining to this vulnerability.
Vendor References
- GHSA-pjh3-jv7w-9jpr -
github.com/advisories/GHSA-pjh3-jv7w-9jpr
CVEs related to QID 980707
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pjh3-jv7w-9jpr | gm |
|