CVE-2021-23422

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-23422
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23422.json
Aliases
Published
2021-08-16T08:15:11Z
Modified
2023-11-29T08:43:58.342217Z
Details

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

References

Affected packages

Git / github.com/tabatkins/bikeshed

Affected ranges

Type
GIT
Repo
https://github.com/tabatkins/bikeshed
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

v0.*

v0.9