CVE-2021-23352
09.03.2021, 19:15
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.
Vendor | Product | Version |
---|---|---|
madge_project | madge | 𝑥 < 4.0.1 |
𝑥
= Vulnerable software versions
References