QID 981945
QID 981945: Nodejs (npm) Security Update for async-git (GHSA-6qpr-9mc5-7gch)
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6qpr-9mc5-7gch for updates pertaining to this vulnerability.
Vendor References
- GHSA-6qpr-9mc5-7gch -
github.com/advisories/GHSA-6qpr-9mc5-7gch
CVEs related to QID 981945
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6qpr-9mc5-7gch | async-git |
|