Description
All versions of package git-archive are vulnerable to Command Injection via the exports function.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-GITARCHIVE-1050391
Related Vulnerabilities
CVE-2020-2221 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-9207 Vulnerability in maven package org.webjars.bowergithub.blueimp:jquery-file-upload
CVE-2021-27906 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-dao
CVE-2023-45279 Vulnerability in maven package org.yamcs:yamcs-core