iTextPDF in iText 7 and up to 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
References
| Link | Resource |
|---|---|
| https://pastebin.com/BXnkY9YY | Exploit Third Party Advisory |
| https://github.com/itext/itext7/releases/tag/7.1.17 | Release Notes Third Party Advisory |
Configurations
Information
Published : 2021-12-15 07:15
Updated : 2022-01-27 14:30
NVD link : CVE-2021-43113
Mitre link : CVE-2021-43113
JSON object : View
Products Affected
itextpdf
- itext
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
