#VU24744 OS Command Injection in codecov - CVE-2020-7596
Published: January 29, 2020
codecov
Codecov
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to the value provided as part of the "gcov-args" argument is executed by the "exec" function within "lib/codecov.js". A remote unauthenticated attacker can execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.