GHSA-h3qr-fjhm-jphw

Suggest an improvement
Source
https://github.com/advisories/GHSA-h3qr-fjhm-jphw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h3qr-fjhm-jphw/GHSA-h3qr-fjhm-jphw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h3qr-fjhm-jphw
Aliases
Published
2022-07-14T00:00:23Z
Modified
2024-11-18T16:26:26Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Codecov does not sanitize gcov arguments
Details

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

Database specific
{
    "severity": "HIGH",
    "github_reviewed": true,
    "nvd_published_at": "2022-07-13T12:15:00Z",
    "cwe_ids": [
        "CWE-88"
    ],
    "github_reviewed_at": "2022-07-15T18:40:09Z"
}
References

Affected packages

PyPI / codecov

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-h3qr-fjhm-jphw/GHSA-h3qr-fjhm-jphw.json"