Command Injection in corenlp-js-interface
Critical severity
GitHub Reviewed
Published
Dec 18, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 11, 2020
Reviewed
Dec 17, 2020
Published to the GitHub Advisory Database
Dec 18, 2020
Last updated
Feb 1, 2023
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
References