9.8
CVSSv3

CVE-2019-10803

Published: 28/02/2020 Updated: 03/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

push-dir up to and including 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an malicious user to inject arbitrary commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

push-dir project push-dir