Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
s3-uploader 操作系统命令注入漏洞
Vulnerability Description
s3-uploader是灵活高效的图像调整大小、重命名和上传到 Amazon S3 磁盘存储。 Turistforeningen node-s3-uploader 2.0.3及之前的版本存在安全漏洞源于Node.js包不安全地将数据传递给 metadata() 函数,该函数最终连接到操作系统命令并在服务器上下文中执行,攻击者利用该漏洞可以执行远程代码。
CVSS Information
N/A
Vulnerability Type
N/A