Description
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Remediation
References
https://hackerone.com/reports/341710
Related Vulnerabilities
CVE-2020-2229 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-45688 Vulnerability in maven package cn.hutool:hutool-json
CVE-2021-27185 Vulnerability in npm package samba-client
CVE-2023-48887 Vulnerability in maven package org.jupiter-rpc:jupiter-rpc
CVE-2020-8237 Vulnerability in maven package org.webjars.npm:json-bigint