
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2020-28451 affects the image-tiler package versions before 2.0.2. This package is designed to create zoom tile pyramids from large images. The vulnerability was discovered by JHU System Security Lab and was disclosed on December 14, 2020 (Snyk).
The vulnerability is classified as a Command Injection vulnerability (CWE-78) with a CVSS v3.1 base score of 9.8 (Critical). The vulnerability is characterized by network attack vector, low attack complexity, no privileges required, and no user interaction needed. The impact spans across confidentiality, integrity, and availability, all rated as high (Snyk).
The vulnerability can result in a total loss of confidentiality, leading to the disclosure of all resources within the impacted component to the attacker. It also causes a complete loss of integrity, allowing attackers to modify protected files, and can result in total loss of availability, enabling attackers to fully deny access to resources (Snyk).
The vulnerability can be remediated by upgrading the image-tiler package to version 2.0.2 or higher. The fix involves changing the use of execSync to execFileSync to prevent command injection attacks (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."