Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1813 | Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content. |
Github GHSA |
GHSA-h42j-mrmp-9369 | git-commit-info vulnerable to Command Injection |
Wed, 27 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-11-27T14:44:55.077Z
Reserved: 2023-02-20T10:28:48.925Z
Link: CVE-2023-26134
Updated: 2024-08-02T11:39:06.594Z
Status : Modified
Published: 2023-06-28T05:15:10.467
Modified: 2024-11-21T07:50:50.807
Link: CVE-2023-26134
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA