QID 982831
QID 982831: Nodejs (npm) Security Update for async-git (GHSA-6c3f-p5wp-34mh)
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6c3f-p5wp-34mh for updates pertaining to this vulnerability.
Vendor References
- GHSA-6c3f-p5wp-34mh -
github.com/advisories/GHSA-6c3f-p5wp-34mh
CVEs related to QID 982831
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6c3f-p5wp-34mh | async-git |
|