CVE-2021-23352: SQL Injection
(updated )
This affects the package madge It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image()
, .svg()
or .dot()
functions are called, is executed by the childprocess.exec
function.
References
Detect and mitigate CVE-2021-23352 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →