Количество 2
Количество 2
CVE-2023-26134
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content.
GHSA-h42j-mrmp-9369
git-commit-info vulnerable to Command Injection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-26134 Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-h42j-mrmp-9369 git-commit-info vulnerable to Command Injection | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу