CVE-2021-23422

Source
https://cve.org/CVERecord?id=CVE-2021-23422
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23422.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-23422
Aliases
Downstream
Related
  • SNYK-PYTHON-BIKESHED-1537646
Published
2021-08-16T08:15:11.287Z
Modified
2026-02-13T08:59:41.898364Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

References

Affected packages

Git / github.com/speced/bikeshed

Affected ranges

Type
GIT
Repo
https://github.com/speced/bikeshed
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23422.json"