Логотип exploitDog
bind:CVE-2020-4059
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-4059

Количество 2

Количество 2

nvd логотип

CVE-2020-4059

больше 5 лет назад

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patched by version 2.0.0. Previous releases are deprecated in npm. As a workaround, make sure to escape git commit messages when using the commitMessage option for the update function.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-qjg4-w4c6-f6c6

больше 5 лет назад

Command injection in mversion

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-4059

In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patched by version 2.0.0. Previous releases are deprecated in npm. As a workaround, make sure to escape git commit messages when using the commitMessage option for the update function.

CVSS3: 7.3
2%
Низкий
больше 5 лет назад
github логотип
GHSA-qjg4-w4c6-f6c6

Command injection in mversion

CVSS3: 7.3
2%
Низкий
больше 5 лет назад

Уязвимостей на страницу