QID 982792
QID 982792: Nodejs (npm) Security Update for im-metadata (GHSA-qfxv-qqvg-24pg)
im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qfxv-qqvg-24pg for updates pertaining to this vulnerability.
Vendor References
- GHSA-qfxv-qqvg-24pg -
github.com/advisories/GHSA-qfxv-qqvg-24pg
CVEs related to QID 982792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qfxv-qqvg-24pg | im-metadata |
|