pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
References
Link | Resource |
---|---|
https://rubygems.org/gems/pdf_info | Product |
https://github.com/affix/CVE-2022-36231 | Exploit Third Party Advisory |
https://github.com/newspaperclub/pdf_info/pull/15 | Patch |
https://github.com/newspaperclub/pdf_info/issues/16 | Patch |
Configurations
Information
Published : 2023-02-23 14:15
Updated : 2023-03-03 11:28
NVD link : CVE-2022-36231
Mitre link : CVE-2022-36231
JSON object : View
CWE
Products Affected
newspaperclub
- pdf_info