GHSA-vqgr-mfxm-47f3

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-vqgr-mfxm-47f3/GHSA-vqgr-mfxm-47f3.json
Aliases
  • CVE-2020-28422
Published
2022-07-26T00:01:06Z
Modified
2022-08-06T05:19:14Z
Details

All versions of package git-archive are vulnerable to Command Injection via the exports function.

References

Affected packages

npm / git-archive

git-archive

Affected ranges

Type
SEMVER
Events
Introduced
0

Affected versions

Database specific

{
    "last_known_affected_version_range": "<= 0.1.4"
}