icon

We found results for “

WS-2020-0136

Date: July 29, 2020

All versions of git-tags-remote (npm package) are vulnerable to command injection. The package doesn't sanitize the repository input and passes it directly. This allows attackers to execute arbitrary code in the system.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Code

CWE-17

Command Injection

CWE-77

Injection

CWE-74

CVSS v3

Base Score:
Attack Vector (AV):
Attack Complexity (AC):
Privileges Required (PR):
User Interaction (UI):
Scope (S):
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): PARTIAL

Do you need more information?

Contact Us