SB2020030417 - Command Injection in push-dir package for npm
Published: March 4, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Command Injection (CVE-ID: CVE-2019-10803)
CWE-ID: CWE-77 - Command injection
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to the arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". A remote attacker can execute arbitrary commands on the target system.Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.