GHSA-rph7-j9qr-h8q8

Suggest an improvement
Source
https://github.com/advisories/GHSA-rph7-j9qr-h8q8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/11/GHSA-rph7-j9qr-h8q8/GHSA-rph7-j9qr-h8q8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rph7-j9qr-h8q8
Aliases
  • CVE-2013-7377
Published
2017-11-28T22:20:17Z
Modified
2023-11-08T03:57:28Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Potential Command Injection in codem-transcode
Details

When the ffprobe functionality is enabled on the server, HTTP POST requests can be made to /probe. These requests are passed to the ffprobe binary on the server. Through this HTTP endpoint it is possible to send a malformed source file name to ffprobe that results in arbitrary command execution.

Mitigating Factors:

The ffprobe functionality is not enabled by default. In addition, exploitation opportunities are limited in a standard configuration because the server binds to the local interface by default.

Recommendation

An updated and patched version of the module (version 0.5.0) is available via npm. Users who have enabled the ffprobe functionality are especially encouraged to upgrade..

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:55:22Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / codem-transcode

Package

Name
codem-transcode
View open source insights on deps.dev
Purl
pkg:npm/codem-transcode

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/11/GHSA-rph7-j9qr-h8q8/GHSA-rph7-j9qr-h8q8.json"