GHSA-7vm7-j8p7-h346

Suggest an improvement
Source
https://github.com/advisories/GHSA-7vm7-j8p7-h346
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-7vm7-j8p7-h346/GHSA-7vm7-j8p7-h346.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7vm7-j8p7-h346
Aliases
Published
2021-05-06T18:27:55Z
Modified
2023-11-08T04:04:14Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Code injection in blamer
Details

Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-04T22:31:46Z",
    "nvd_published_at": "2020-03-20T19:15:00Z",
    "severity": "HIGH"
}
References

Affected packages

npm / blamer

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.1

Database specific

last_known_affected_version_range
"<= 1.0.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-7vm7-j8p7-h346/GHSA-7vm7-j8p7-h346.json"