Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52qp-gwwh-qrg4

Опубликовано: 21 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.2

Описание

Missing Handler in @scandipwa/magento-scripts

Impact

After changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec and logs commands, effectively making them unusable.

Patches

Version 1.5.3 contains patches for the problems described above.

Workarounds

Upgrade to patched or latest (recommended) version npm i @scandipwa/magento-scripts@1.5.3 or npm i @scandipwa/magento-scripts@latest.

References

New releases always available here: https://github.com/scandipwa/create-magento-app/releases

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

@scandipwa/magento-scripts

npm
Затронутые версииВерсия исправления

>= 1.5.1, < 1.5.3

1.5.3

EPSS

Процентиль: 41%
0.00189
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 6.2
nvd
больше 4 лет назад

magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which allows one to deploy Magento 2. In versions 1.5.1 and 1.5.2, after changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec, and logs commands, effectively making them unusable. Version 1.5.3 contains patches for the problems.

EPSS

Процентиль: 41%
0.00189
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-670