QID 981808
QID 981808: Nodejs (npm) Security Update for gitlogplus (GHSA-3fxp-vwxm-2r5p)
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3fxp-vwxm-2r5p for updates pertaining to this vulnerability.
Vendor References
- GHSA-3fxp-vwxm-2r5p -
github.com/advisories/GHSA-3fxp-vwxm-2r5p
CVEs related to QID 981808
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3fxp-vwxm-2r5p | gitlogplus |
|