Arbitrary Code Injection Affecting pdf_info package, versions >=0.0.0
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.43% (76th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-PDFINFO-3330768
- published 24 Feb 2023
- disclosed 24 Feb 2023
- credit Unknown
Introduced: 24 Feb 2023
CVE-2022-36231 Open this link in a new tabHow to fix?
There is no fixed version for pdf_info
.
Overview
Affected versions of this package are vulnerable to Arbitrary Code Injection such that an attacker using a specially crafted payload may execute OS commands by using command chaining because during object initalization, there is no validation performed and the user provided path is used.
References
CVSS Scores
version 3.1