Description
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Remediation
References
https://hackerone.com/reports/341710
Related Vulnerabilities
CVE-2023-29204 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-36179 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-3163 Vulnerability in maven package com.ruoyi:ruoyi-common
CVE-2023-5573 Vulnerability in npm package @vrite/sdk
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet