Blamer
Blamer Project · 3 CVEs
CVE-2023-26143
CRITICAL
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. T…
Sep 19, 2023
CVE-2020-8137
HIGH
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be cont…
Mar 20, 2020
CVE-2019-10807
CRITICAL
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as p…
Mar 10, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-26143 | Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user in… | CRITICAL | 1.12% | Sep 19, 2023 |
| CVE-2020-8137 | Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. | HIGH | 4.27% | Mar 20, 2020 |
| CVE-2019-10807 | Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer. | CRITICAL | 2.42% | Mar 10, 2020 |
Showing 1 to 3 of 3 CVEs