Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49q3-8867-5wmp

Опубликовано: 08 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Remote Command Execution in reg-keygen-git-hash-plugin

Impact

reg-keygen-git-hash-plugin through 0.10.15 allow remote attackers to execute of arbitrary commands.

Patches

Upgrade to version 0.10.16 or later.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

reg-keygen-git-hash-plugin

npm
Затронутые версииВерсия исправления

< 0.10.16

0.10.16

EPSS

Процентиль: 82%
0.01795
Низкий

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade to version 0.10.16 or later to resolve this issue.

EPSS

Процентиль: 82%
0.01795
Низкий

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94