Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 RubyGems

Code injection in pdf_info

GHSA-9fh3-j99m-f4v7 · CVE-2022-36231

Published · Modified

Description

pdf_info 0.5.3 is vulnerable to Command Execution. An attacker using a specially crafted payload may execute OS commands by using command chaining because during object initalization there is no validation performed and the user provided path is used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes