CVE-2019-10776
Summary
| CVE | CVE-2019-10776 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-07 19:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Page not found | Snyk |
|
snyk.io |
|
| Invalid vulnerability |
CONFIRM |
snyk.io |
Broken Link |
| spawn git clone · kellyselden/git-diff-apply@106d61d · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Command Injection in git-diff-apply | Snyk |
MISC |
snyk.io |
Exploit, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981591 Nodejs (npm) Security Update for git-diff-apply (GHSA-84cm-v6jp-gjmr)