vendor:
Angular-Base64-Upload Library
by:
Ravindu Wickramasinghe
CVSS
Unauthenticated Remote Code Execution (RCE)
284
CWE
Product Name: Angular-Base64-Upload Library
Affected Version From: prior to v0.1.21
Affected Version To: v0.1.21
Patch Exists: YES
Related CWE: CVE-2024-42640
CPE: a:angular-base64-upload:angular-base64-upload:0.1.20
Platforms Tested: Arch Linux
2024
Angular-Base64-Upload Library 0.1.21 – Unauthenticated Remote Code Execution (RCE)
The Angular-Base64-Upload Library version 0.1.21 and prior is vulnerable to unauthenticated remote code execution (RCE). An attacker can exploit this vulnerability to execute arbitrary code on the target system without authentication. This exploit has been assigned CVE-2024-42640.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Angular-Base64-Upload Library to version 0.1.21 or later. Additionally, restrict access to the vulnerable component to trusted entities only.