Description
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4780
https://www.npmjs.com/package/gitsome
Related Vulnerabilities
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2020-15096 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors
CVE-2019-17558 Vulnerability in maven package org.apache.solr:solr-velocity
CVE-2023-39619 Vulnerability in npm package node-email-check