Critical severity9.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2021-34084
CVE-2021-34084
Description
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
s3-uploadernpm | <= 2.0.3 | — |
Affected products
3- cpe:2.3:a:s3-uploader_project:s3-uploader:*:*:*:*:*:node.js:*:*Range: <=2.0.3
- Turistforeningen/node-s3-uploaderdescription
Patches
Vulnerability mechanics
References
3- advisory.checkmarx.net/advisory/CX-2021-4776nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gwp3-f7mr-qpfvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-34084ghsaADVISORY
News mentions
0No linked articles in our index yet.