CVE-2018-25083

EPSS 17.6%

pullit vulnerable to command injection

發布日:2020/9/3修改日:2023/11/8

描述

Versions of `pullit` prior to 1.4.0 are vulnerable to Command Injection. The package does not validate input on git branch names and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system. ## Recommendation Upgrade to version 1.4.0 or later. ## Credits This vulnerability was discovered by @lirantal

受影響套件(1)

參考連結(6)