Security Advisory

CVE-2021-3190

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-01-21 07:11:33
Last updated 2024-08-03 16:45:51
Assigner mitre
State PUBLISHED

Description

The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.