QID 981900
QID 981900: Nodejs (npm) Security Update for get-git-data (GHSA-wj6h-7chw-x4h2)
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wj6h-7chw-x4h2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-wj6h-7chw-x4h2 -
github.com/advisories/GHSA-wj6h-7chw-x4h2
CVEs related to QID 981900
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wj6h-7chw-x4h2 | get-git-data |
|