Description
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4780
https://www.npmjs.com/package/gitsome
Related Vulnerabilities
CVE-2023-46498 Vulnerability in npm package @evershop/evershop
CVE-2020-14967 Vulnerability in npm package jsrsasign
CVE-2022-22138 Vulnerability in npm package fast-string-search
CVE-2020-15119 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2023-35150 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui