CVE-2020-7601
15.03.2020, 22:15
gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.
Vendor | Product | Version |
---|---|---|
gulp-scss-lint_project | gulp-scss-lint | 𝑥 ≤ 1.0.0 |
𝑥
= Vulnerable software versions