Known Vulnerabilities for products from Codecov
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Codecov".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-15123 json | In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov... | 9.3 - CRITICAL | 2020-07-20 | 2020-07-27 |
| CVE-2020-7597 json | codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the ... | 8.8 - HIGH | 2020-02-17 | 2020-02-20 |
| CVE-2020-7596 json | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | 8.8 - HIGH | 2020-01-25 | 2021-07-21 |
| CVE-2019-10800 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2022-07-13 | 2022-11-08 |
Known software with vulnerabilities from Codecov
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Codecov | Codecov | 1.0.0 |
| Application | Codecov | Nodejs Uploader | 3.6.2 |