Do your applications use this vulnerable package?
Test your applications
Overview
async-git is a 👾 Retrieve data from current git repository
Affected versions of this package are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('a
touch HACKEDb')
Remediation
Upgrade async-git
to version 1.13.2 or higher.
References
CVSS Score
9.1
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityNone
- Credit
- Omri Lotan, Adar-Checkmarx
- CVE
- CVE-2020-28490
- CWE
- CWE-78
- Snyk ID
- SNYK-JS-ASYNCGIT-1064877
- Disclosed
- 26 Jan, 2021
- Published
- 26 Jan, 2021