QID 983384
QID 983384: Nodejs (npm) Security Update for pdf-image (GHSA-5gwh-g79j-vh4q)
Versions of `pdf-image` before 2.0.0 are vulnerable to command injection. This vulnerability is exploitable if the attacker has control over the `pdfFilePath` variable passed into `pdf-image`.
## Recommendation
Update to version 2.0.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5gwh-g79j-vh4q for updates pertaining to this vulnerability.
Vendor References
- GHSA-5gwh-g79j-vh4q -
github.com/advisories/GHSA-5gwh-g79j-vh4q
CVEs related to QID 983384
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5gwh-g79j-vh4q | pdf-image |
|