CVE-2021-23422

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bikeshed_project:bikeshed:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-08-16 08:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-23422

Mitre link : CVE-2021-23422

CVE.ORG link : CVE-2021-23422


JSON object : View

Products Affected

bikeshed_project

  • bikeshed
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')