fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
References
Link | Resource |
---|---|
https://nodesecurity.io/advisories/360 | Issue Tracking Patch Third Party Advisory |
https://nodesecurity.io/advisories/360 | Issue Tracking Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 03:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://nodesecurity.io/advisories/360 - Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2018-01-02 17:29
Updated : 2024-11-21 03:04
NVD link : CVE-2017-1000451
Mitre link : CVE-2017-1000451
CVE.ORG link : CVE-2017-1000451
JSON object : View
Products Affected
fs-git_project
- fs-git
CWE