CVE-2021-23412 Information
Jun 07, 2022
cve
Description
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality as options attributes are appended to the command to be executed without sanitization.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://snyk.io/vuln/SNYK-JS-GITLOGPLUS-1315832 https://hackerone.com/reports/808942 https://www.npmjs.com/package/gitlogplus
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: