Command Injection Affecting last-commit-log package, versions *
Threat Intelligence
Exploit Maturity
Proof of concept
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-LASTCOMMITLOG-1047325
- published 29 Nov 2020
- disclosed 29 Nov 2020
- credit bilk0h
How to fix?
There is no fixed version for last-commit-log
.
Overview
last-commit-log is a Node.js module to get the last git commit information - mostly to be used by CI/CD and building phase
Affected versions of this package are vulnerable to Command Injection via the GIT_DIR
env variable.
References
CVSS Scores
version 3.1