VDB
Sign up
—

GO-2022-1184

OS command injection vulnerability in code.sajari.com/docconv

Quick fix

GO-2022-1184 — code.sajari.com/docconv: upgrade to the fixed version with the command below.

go get code.sajari.com/docconv@v1.3.5

Details

The manipulation of the argument path to docconv.{ConvertPDF,PDFHasImage} leads to os command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/code.sajari.com/docconv
Introduced in: 1.1.0Fixed in: 1.3.5
Fixgo get code.sajari.com/docconv@v1.3.5

References