Vulnerability CVE-2021-23412


Published: 2021-07-23

Description:
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

 References:
https://snyk.io/vuln/SNYK-JS-GITLOGPLUS-1315832
https://hackerone.com/reports/808942
https://www.npmjs.com/package/gitlogplus

Copyright 2024, cxsecurity.com

 

Back to Top