QID 983971
QID 983971: Nodejs (npm) Security Update for git-dummy-commit (GHSA-h3c2-x77c-7pvr)
A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h3c2-x77c-7pvr for updates pertaining to this vulnerability.
Vendor References
- GHSA-h3c2-x77c-7pvr -
github.com/advisories/GHSA-h3c2-x77c-7pvr
CVEs related to QID 983971
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h3c2-x77c-7pvr | git-dummy-commit |
|