Description
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4780
https://www.npmjs.com/package/gitsome
Related Vulnerabilities
CVE-2021-23384 Vulnerability in npm package koa-remove-trailing-slashes
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-21810 Vulnerability in npm package smartctl
CVE-2020-15231 Vulnerability in maven package org.mapfish.print:print-servlet
CVE-2022-41710 Vulnerability in npm package electron-markdownify