Описание
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
8.1 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
The package cookiecutter before 2.1.1 are vulnerable to Command Inject ...
EPSS
8.1 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2