Описание
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-api-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-api-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-api-rhel8 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1925227graphql-tools/git-loader: exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
EPSS
Процентиль: 81%
0.01502
Низкий
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 6.3
nvd
около 5 лет назад
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
EPSS
Процентиль: 81%
0.01502
Низкий
8.8 High
CVSS3