CVE-2015-7982
Command Injection in gm
描述
Versions of `gm` prior to 1.21.1 are affected by a command injection vulnerability. The vulnerability is triggered when user input is passed into `gm.compare()`, which fails to sanitize input correctly before calling the graphics magic binary. ## Recommendation Update to version 1.21.1 or later.
如何修補 CVE-2015-7982
要修補 CVE-2015-7982,請將受影響套件升級到下列已修補版本。
- npm/gm—升級至 1.21.1 或更新版本
CVE-2015-7982 正在被利用嗎?
目前沒有被利用訊號。CVE-2015-7982 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0, < 1.21.1