QID 995607
Date Published: 2023-10-18
QID 995607: NodeJs (Npm) Security Update for node-qpdf (GHSA-fpr8-4wvx-j9q3)
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fpr8-4wvx-j9q3 for updates and patch information.
Vendor References
- GHSA-fpr8-4wvx-j9q3 -
github.com/advisories/GHSA-fpr8-4wvx-j9q3
CVEs related to QID 995607
Software Advisories
| Advisory ID | Software | Component | Link |
|---|