Логотип exploitDog
bind:CVE-2024-21532
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21532

Количество 2

Количество 2

nvd логотип

CVE-2024-21532

больше 1 года назад

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-62cx-5xj4-wfm4

больше 1 года назад

ggit is vulnerable to Command Injection via the fetchTags(branch) API

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21532

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-62cx-5xj4-wfm4

ggit is vulnerable to Command Injection via the fetchTags(branch) API

CVSS3: 7.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу