GHSA-xmxh-g7wj-8m4m

Suggest an improvement
Source
https://github.com/advisories/GHSA-xmxh-g7wj-8m4m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-xmxh-g7wj-8m4m/GHSA-xmxh-g7wj-8m4m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xmxh-g7wj-8m4m
Aliases
  • CVE-2019-10789
Published
2021-04-13T15:32:26Z
Modified
2023-11-08T04:00:57Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OS Command Injection in curling
Details

npm package curling before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-03-31T23:13:03Z",
    "nvd_published_at":  "2020-02-06T16:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / curling

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.1.0

Database specific

last_known_affected_version_range
"<= 1.0.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-xmxh-g7wj-8m4m/GHSA-xmxh-g7wj-8m4m.json"