ZeroHour

CVE-2019-10800

PoC
CVSS 3.1
6.5 medium
EPSS
1%p66
Published
()
Modified
Description

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

Vendors
codecov
Products
codecov-python
Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.