Description
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Remediation
References
https://hackerone.com/reports/341710
Related Vulnerabilities
CVE-2021-27515 Vulnerability in maven package org.webjars.npm:url-parse
CVE-2022-0087 Vulnerability in npm package @keystone-6/auth
CVE-2020-13929 Vulnerability in maven package org.apache.zeppelin:zeppelin
CVE-2021-23376 Vulnerability in npm package ffmpegdotjs
CVE-2023-26486 Vulnerability in maven package org.webjars.bowergithub.vega:vega