PT-2021-17029 · Wayfair · Git-Parse
Published
2021-05-06
·
Updated
2022-07-12
·
CVE-2021-26543
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wayfair git-parse versions 1.0.0 through 1.0.4
Description
The issue is related to a command injection vulnerability in the
gitDiff function. This vulnerability can affect clients of the git-parse library, as they may unknowingly write vulnerable code.Recommendations
For versions 1.0.0 through 1.0.4, update to version 1.0.5 to resolve the issue.
As a temporary workaround, consider disabling the
gitDiff function until a patch is available.Exploit
Fix
Special Elements Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Git-Parse