CVE-2018-25083
27.03.2023, 03:15
The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.
Vendor | Product | Version |
---|---|---|
pull_it_project | pull_it | 𝑥 < 1.4.0 |
𝑥
= Vulnerable software versions