Command Injection Affecting ntesseract package, versions <0.2.9
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.17% (55th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-NTESSERACT-1050982
- published 26 Jan 2021
- disclosed 14 Dec 2020
- credit JHU System Security Lab
Introduced: 14 Dec 2020
CVE-2020-28446 Open this link in a new tabHow to fix?
Upgrade ntesseract
to version 0.2.9 or higher.
Overview
ntesseract is a simple wrapper for the Tesseract OCR package for node.js
Affected versions of this package are vulnerable to Command Injection via lib/tesseract.js
.
PoC:
var a =require("ntesseract");
a.process("& touch JHU #","",function(){})
References
CVSS Scores
version 3.1