CVE-2019-5485
Command Injection in gitlabhook
10.0
CRITICAL
CVSS 3.1
EPSS 59.8%
描述
All versions of `gitlabhook` are vulnerable to Command Injection. The package does not validate input the body of POST request and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system. ## Recommendation No fix is currently available. Consider using an alternative package until a fix is made available.
如何修補 CVE-2019-5485
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- —未列出修補版本
CVE-2019-5485 正在被利用嗎?
可能 — EPSS 為 59.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, <= 0.0.17
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |