CVE-2021-3190
26.01.2021, 18:16
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Vendor | Product | Version |
---|---|---|
async-git_project | async-git | 𝑥 < 1.13.2 |
𝑥
= Vulnerable software versions
References