CVE-2021-3190
Summary
| CVE | CVE-2021-3190 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:16:00 UTC |
| Updated | 2022-04-29 19:26:00 UTC |
| Description | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Add test for reported vulnerabilities by omrilotan · Pull Request #13 · omrilotan/async-git · GitHub |
MISC |
github.com |
Third Party Advisory |
| Add test for reported vulnerabilities by omrilotan · Pull Request #13 · omrilotan/async-git · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Add test for reported vulnerabilities by omrilotan · Pull Request #13 · omrilotan/async-git · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| advisory.checkmarx.net/advisory/CX-2021-4772 |
MISC |
advisory.checkmarx.net |
|
| Use spawn with git to avoid shell script vulnerabilities by omrilotan · Pull Request #14 · omrilotan/async-git · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982831 Nodejs (npm) Security Update for async-git (GHSA-6c3f-p5wp-34mh)