Описание
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.13.2 (исключая)
cpe:2.3:a:async-git_project:async-git:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 95%
0.20943
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
EPSS
Процентиль: 95%
0.20943
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78