CVE-2023-26143
Summary
| CVE | CVE-2023-26143 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-19 05:17:00 UTC |
| Updated | 2023-11-07 04:09:00 UTC |
| Description | Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Arbitrary Argument Injection in blamer | CVE-2023-26143 | Snyk |
MISC |
security.snyk.io |
|
| Argument Injection vulnerability in `[email protected]` · GitHub |
MISC |
gist.github.com |
|
| fix(vulnerability): https://gist.github.com/lirantal/14c3686370a86461… · kucherenko/blamer@0965877 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995348 NodeJs (Npm) Security Update for blamer (GHSA-6f9p-g466-f8v8)