Description
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CODECOV-543183
Related Vulnerabilities
CVE-2020-9495 Vulnerability in maven package org.apache.archiva:archiva
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private