{"id":"GHSA-gv87-q66h-4277","summary":"Command injection in itext7-core","details":"iTextPDF in iText before 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.","aliases":["CVE-2021-43113"],"modified":"2023-11-01T05:29:34.946517Z","published":"2021-12-16T00:02:15Z","database_specific":{"cwe_ids":["CWE-77"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-01-25T21:02:25Z","nvd_published_at":"2021-12-15T07:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43113"},{"type":"PACKAGE","url":"https://github.com/itext/itext7"},{"type":"WEB","url":"https://github.com/itext/itext7/releases/tag/7.1.17"},{"type":"WEB","url":"https://github.com/itext/itextpdf/releases/tag/5.5.13.3"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/01/msg00013.html"},{"type":"WEB","url":"https://pastebin.com/BXnkY9YY"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5323"}],"affected":[{"package":{"name":"com.itextpdf:itext7-core","ecosystem":"Maven","purl":"pkg:maven/com.itextpdf/itext7-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.17"}]}],"versions":["7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.1.0","7.1.1","7.1.10","7.1.11","7.1.12","7.1.13","7.1.14","7.1.15","7.1.16","7.1.2","7.1.3","7.1.4","7.1.5","7.1.6","7.1.7","7.1.8","7.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-gv87-q66h-4277/GHSA-gv87-q66h-4277.json"}},{"package":{"name":"com.itextpdf:itextpdf","ecosystem":"Maven","purl":"pkg:maven/com.itextpdf/itextpdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.13.3"}]}],"versions":["5.0.6","5.1.0","5.1.1","5.1.2","5.1.3","5.2.0","5.2.1","5.3.0","5.3.1","5.3.2","5.3.4","5.4.0","5.4.1","5.4.2","5.4.3","5.4.4","5.4.5","5.5.0","5.5.1","5.5.10","5.5.11","5.5.12","5.5.13","5.5.13.1","5.5.13.2","5.5.2","5.5.3","5.5.4","5.5.5","5.5.6","5.5.7","5.5.8","5.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-gv87-q66h-4277/GHSA-gv87-q66h-4277.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}