CVE-2021-34084

EPSS 14.7%

OS Command Injection in s3-uploader

Published: 6/3/2022Modified: 11/8/2023
Also known as:GHSA-gwp3-f7mr-qpfv

Description

OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.

Affected packages (1)

References (3)