QID 981911
QID 981911: Nodejs (npm) Security Update for gulp-scss-lint (GHSA-g4hj-r7r3-9rwv)
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g4hj-r7r3-9rwv for updates pertaining to this vulnerability.
Vendor References
- GHSA-g4hj-r7r3-9rwv -
github.com/advisories/GHSA-g4hj-r7r3-9rwv
CVEs related to QID 981911
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g4hj-r7r3-9rwv | gulp-scss-lint |
|