Command injection in itext7-core
Critical severity
GitHub Reviewed
Published
Dec 16, 2021
to the GitHub Advisory Database
•
Updated Mar 27, 2023
Description
Published by the National Vulnerability Database
Dec 15, 2021
Published to the GitHub Advisory Database
Dec 16, 2021
Reviewed
Jan 25, 2022
Last updated
Mar 27, 2023
iTextPDF in iText before 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
References