ZeroHour

CVE-2019-10802

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.

Vendors
mangoraft
Products
giting
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.