This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537646 | Patch Third Party Advisory |
https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cb6b2dd | Patch Third Party Advisory |
Configurations
Information
Published : 2021-08-16 01:15
Updated : 2021-08-23 12:02
NVD link : CVE-2021-23422
Mitre link : CVE-2021-23422
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
bikeshed_project
- bikeshed