CVE-2021-3190
EUVD-2021-049326.01.2021, 18:16
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| async-git_project | async-git | 𝑥 < 1.13.2 |
𝑥
= Vulnerable software versions
References