QID 981591
QID 981591: Nodejs (npm) Security Update for git-diff-apply (GHSA-84cm-v6jp-gjmr)
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-84cm-v6jp-gjmr for updates pertaining to this vulnerability.
Vendor References
- GHSA-84cm-v6jp-gjmr -
github.com/advisories/GHSA-84cm-v6jp-gjmr
CVEs related to QID 981591
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-84cm-v6jp-gjmr | git-diff-apply |
|