Количество 3
Количество 3
CVE-2021-23326
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
CVE-2021-23326
This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.
GHSA-vhhw-xjvf-wprr
Command Injection in @graphql-tools/git-loader
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-23326 This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection. | CVSS3: 8.8 | 2% Низкий | около 5 лет назад | |
CVE-2021-23326 This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection. | CVSS3: 6.3 | 2% Низкий | около 5 лет назад | |
GHSA-vhhw-xjvf-wprr Command Injection in @graphql-tools/git-loader | CVSS3: 8.8 | 2% Низкий | около 5 лет назад |
Уязвимостей на страницу