Vulnerabilities/

Nadesiko3 OS Command Injection vulnerability

Severity:
High

Description

OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.68 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

Release notes for versions 3.3.62 and 3.3.69 both link to patches for this particular issue. The JPCERT/CC advisory lists versions 3.3.

Recommendation

Update the nadesiko3 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nadesiko3
Anything's wrong? Let us know Last updated on January 31, 2023

This issue is available in SmartScanner Professional

See Pricing