s3-uploader@0.4.2 vulnerabilities

Resize, rename, and upload images to AWS S3

Direct Vulnerabilities

Known vulnerabilities in the s3-uploader package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • C
Command Injection

s3-uploader is a Flexible and efficient image resize, rename, and upload to Amazon S3 disk storage. Uses the official AWS Node SDK, and im-resize and im-metadata for image processing.

Affected versions of this package are vulnerable to Command Injection which insecurely passes data to the metadata() function. It is then concatenated to an OS command and executed in the context of the server.

How to fix Command Injection?

There is no fixed version for s3-uploader.
