Description
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
Remediation
References
http://packetstormsecurity.com/files/154598/NPMJS-gitlabhook-0.0.17-Remote-Command-Execution.html
https://hackerone.com/reports/685447
Related Vulnerabilities
CVE-2018-3720 Vulnerability in npm package assign-deep
CVE-2020-26217 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2021-31597 Vulnerability in npm package xmlhttprequest-ssl
CVE-2021-44832 Vulnerability in maven package org.apache.logging.log4j:log4j-core