
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2020-28494 affects the total.js package versions before 3.4.7. The issue was discovered in the image.pipe and image.stream functions, where the type parameter is used to build commands that are executed using child_process.spawn. The vulnerability was disclosed on January 29, 2021 (Snyk Report).
The vulnerability occurs because child_process.spawn is called with the option shell set to true and the type parameter is not properly sanitized. This implementation flaw allows for potential command injection attacks. The vulnerability has been assigned a CVSS v3.1 score of 8.6 (HIGH) by Snyk, indicating significant severity (Snyk Report).
A successful exploitation of this vulnerability could result in command injection, potentially leading to arbitrary code execution on the affected system. The attack could result in total loss of confidentiality with high impact, while having lower impact on system integrity and availability (Snyk Report).
The vulnerability is remotely exploitable and requires no special privileges or user interaction. Snyk has confirmed the existence of a proof-of-concept exploit, indicating that the vulnerability is practically exploitable (Snyk Report).
The vulnerability has been fixed in total.js version 3.4.7. Users are recommended to upgrade to this version or higher to mitigate the risk. The fix includes proper validation of supported image types through a whitelist implementation (Github Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."