QID 980875
QID 980875: Nodejs (npm) Security Update for codem-transcode (GHSA-rph7-j9qr-h8q8)
When the ffprobe functionality is enabled on the server, HTTP POST requests can be made to /probe. These requests are passed to the ffprobe binary on the server. Through this HTTP endpoint it is possible to send a malformed source file name to ffprobe that results in arbitrary command execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rph7-j9qr-h8q8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rph7-j9qr-h8q8 -
github.com/advisories/GHSA-rph7-j9qr-h8q8
CVEs related to QID 980875
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rph7-j9qr-h8q8 | codem-transcode |
|