Arbitrary Code Injection Affecting pdf_info package, versions >=0.0.0


0.0
high

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    Exploit Maturity Proof of concept
    EPSS 0.24% (62nd percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-RUBY-PDFINFO-3330768
  • published 24 Feb 2023
  • disclosed 24 Feb 2023
  • credit Unknown

How to fix?

There is no fixed version for pdf_info.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Injection such that an attacker using a specially crafted payload may execute OS commands by using command chaining because during object initalization, there is no validation performed and the user provided path is used.

References