QID 995348
Date Published: 2023-09-22
QID 995348: NodeJs (Npm) Security Update for blamer (GHSA-6f9p-g466-f8v8)
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6f9p-g466-f8v8 for updates and patch information.
Vendor References
- GHSA-6f9p-g466-f8v8 -
github.com/advisories/GHSA-6f9p-g466-f8v8
CVEs related to QID 995348
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6f9p-g466-f8v8 | blamer |
|