CVE-2019-5485
Summary
| CVE | CVE-2019-5485 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-13 18:15:00 UTC |
| Updated | 2023-02-28 19:36:00 UTC |
| Description | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983396 Nodejs (npm) Security Update for gitlabhook (GHSA-549f-73hh-mj38)