QID 981588
QID 981588: Nodejs (npm) Security Update for codecov (GHSA-5q88-cjfq-g2mh)
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5q88-cjfq-g2mh for updates pertaining to this vulnerability.
Vendor References
- GHSA-5q88-cjfq-g2mh -
github.com/advisories/GHSA-5q88-cjfq-g2mh
CVEs related to QID 981588
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5q88-cjfq-g2mh | codecov |
|