Description
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
Remediation
References
https://www.npmjs.com/package/gitlog
https://github.com/domharrington/node-gitlog/pull/65
https://advisory.checkmarx.net/advisory/CX-2020-4301
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.npm:github-com-layui-layui
CVE-2019-0191 Vulnerability in maven package org.apache.karaf.kar:org.apache.karaf.kar.core
CVE-2019-20174 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2021-23490 Vulnerability in npm package parse-link-header
CVE-2017-15682 Vulnerability in maven package org.craftercms:crafter-studio