Количество 2
Количество 2
CVE-2021-23420
больше 4 лет назад
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
CVSS3: 7.7
EPSS: Низкий
GHSA-4574-qv3w-fcmg
больше 4 лет назад
Deserialization of Untrusted Data in codeception/codeception
CVSS3: 9.8
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-23420 This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation. | CVSS3: 7.7 | 1% Низкий | больше 4 лет назад | |
GHSA-4574-qv3w-fcmg Deserialization of Untrusted Data in codeception/codeception | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу
20