CRITICAL
Command Injection
Published Feb 18, 2021
9.8
CRITICALCVSS 3.1
EPSS 2.55%
Description
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
Affected products
- Vendor n/a Product Async-Git Defaultn/a
- Version unspecifiedStatusaffectedConstraints<1.13.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Async-Git | n/a |
|
- < 1.13.2
No data.
No Red Hat product state for this CVE.
async-git
npm
Introduced 0 Fixed 1.13.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | async-git | 0 | 1.13.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0777 Advisory
- https://github.com/advisories/GHSA-6qpr-9mc5-7gch Advisory
- https://github.com/omrilotan/async-git/commit/d1950a5021f4e19d92f347614be0d85ce991510d x_refsource_MISCPatchThird Party Advisory
- https://github.com/omrilotan/async-git/pull/14 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28490
- https://snyk.io/vuln/SNYK-JS-ASYNCGIT-1064877 x_refsource_MISCPatchThird Party Advisory
- https://www.npmjs.com/package/async-git
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0777 | Advisory | |
| https://github.com/advisories/GHSA-6qpr-9mc5-7gch | Advisory | |
| https://github.com/omrilotan/async-git/commit/d1950a5021f4e19d92f347614be0d85ce991510d | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/omrilotan/async-git/pull/14 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-28490 | ||
| https://snyk.io/vuln/SNYK-JS-ASYNCGIT-1064877 | x_refsource_MISCPatchThird Party Advisory | |
| https://www.npmjs.com/package/async-git |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Feb 18, 2021
Updated Sep 17, 2024
Reserved Nov 12, 2020
Link CVE-2020-28490
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-0777 GHSA-6QPR-9MC5-7GCH Assigner snyk
Published Feb 18, 2021
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2021-0777