git-ls-remote@0.0.1 vulnerabilities

A very simple interface to git ls-remote

  • latest version

    0.2.0

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    8 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the git-ls-remote package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Shell Command Injection

    git-ls-remote is an npm package used for listing references in a remote git repository. Vulnerable versions of the package pass the git url argument to the exec function without sanitisation. An attacker can use this to inject malicious shell commands to disrupt server operation or obtain sensitive information.

    How to fix Shell Command Injection?

    Upgrade git-ls-remote to version 0.2.0 or higher.

    <0.2.0