Описание
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:gitlabhook_project:gitlabhook:0.0.17:*:*:*:*:node.js:*:*
EPSS
Процентиль: 97%
0.40695
Средний
10 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78
Связанные уязвимости
EPSS
Процентиль: 97%
0.40695
Средний
10 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78