Описание
Command injection in gitlogplus
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
Пакеты
Наименование
gitlogplus
npm
Затронутые версииВерсия исправления
<= 3.1.7
Отсутствует
Связанные уязвимости
CVSS3: 8.1
nvd
больше 4 лет назад
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.