A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of the file app.js. The manipulation leads to os command injection. Upgrading to version 2.2.0 is able to address this issue. The patch is identified as 29d9c25415911ea2f8b6de247cb5c4607d13d434. It is recommended to upgrade the affected component. VDB-248278 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/pedroetb/tts-api/commit/29d9c25415911ea2f8b6de247cb5c4607d13d434 | Patch |
https://github.com/pedroetb/tts-api/releases/tag/v2.2.0 | Release Notes |
https://vuldb.com/?ctiid.248278 | Permissions Required |
https://vuldb.com/?id.248278 | Third Party Advisory |
https://github.com/pedroetb/tts-api/commit/29d9c25415911ea2f8b6de247cb5c4607d13d434 | Patch |
https://github.com/pedroetb/tts-api/releases/tag/v2.2.0 | Release Notes |
https://vuldb.com/?ctiid.248278 | Permissions Required |
https://vuldb.com/?id.248278 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pedroetb/tts-api/commit/29d9c25415911ea2f8b6de247cb5c4607d13d434 - Patch | |
References | () https://github.com/pedroetb/tts-api/releases/tag/v2.2.0 - Release Notes | |
References | () https://vuldb.com/?ctiid.248278 - Permissions Required | |
References | () https://vuldb.com/?id.248278 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.2
v3 : 5.5 |
28 Dec 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://vuldb.com/?ctiid.248278 - Permissions Required | |
References | () https://vuldb.com/?id.248278 - Third Party Advisory | |
References | () https://github.com/pedroetb/tts-api/releases/tag/v2.2.0 - Release Notes | |
References | () https://github.com/pedroetb/tts-api/commit/29d9c25415911ea2f8b6de247cb5c4607d13d434 - Patch | |
CPE | cpe:2.3:a:pedroetb:tts-api:*:*:*:*:*:*:*:* | |
First Time |
Pedroetb
Pedroetb tts-api |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
19 Dec 2023, 13:42
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-19 13:15
Updated : 2024-11-21 04:40
NVD link : CVE-2019-25158
Mitre link : CVE-2019-25158
CVE.ORG link : CVE-2019-25158
JSON object : View
Products Affected
pedroetb
- tts-api
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')