Lucene search

K
cvelistSnykCVELIST:CVE-2022-24429
HistoryJun 10, 2022 - 8:00 p.m.

CVE-2022-24429 Arbitrary Code Injection

2022-06-1020:00:38
snyk
www.cve.org
2
arbitrary code injection
svg file
png file
file system access

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P

EPSS

0.001

Percentile

50.3%

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

CNA Affected

[
  {
    "product": "convert-svg-core",
    "vendor": "n/a",
    "versions": [
      {
        "lessThan": "0.6.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P

EPSS

0.001

Percentile

50.3%

Related for CVELIST:CVE-2022-24429