Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01NHB4LW1od3YtNXY4eM4AArfq
Code injection via SVG file in convert-svg-core
The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.
Permalink: https://github.com/advisories/GHSA-54px-mhwv-5v8xJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NHB4LW1od3YtNXY4eM4AArfq
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 2 years ago
Updated: almost 2 years ago
CVSS Score: 8.6
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS Percentage: 0.00135
EPSS Percentile: 0.49509
Identifiers: GHSA-54px-mhwv-5v8x, CVE-2022-24429
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-24429
- https://github.com/neocotic/convert-svg/issues/84
- https://github.com/neocotic/convert-svg/commit/a43dffaab0f1e419d5be84e2e7356b86ffac3cf1
- https://snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2859212
- https://github.com/advisories/GHSA-54px-mhwv-5v8x
Blast Radius: 20.2
Affected Packages
npm:convert-svg-core
Dependent packages: 4Dependent repositories: 224
Downloads: 34,297 last month
Affected Version Ranges: < 0.6.3
Fixed in: 0.6.3
All affected versions: 0.3.0, 0.3.1, 0.3.2, 0.3.3, 0.4.0, 0.5.0, 0.6.0, 0.6.1, 0.6.2
All unaffected versions: 0.6.3, 0.6.4