This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
{
"cpe": "cpe:2.3:a:codecov:codecov-python:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.0.16"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}