漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Command Injection
Vulnerability Description
All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
git-promise 参数注入漏洞
Vulnerability Description
git-promise是一个简单的包装器。使用更直观的语法运行任何 git 命令 git-promise 所有版本存在参数注入漏洞,该漏洞源于拉取请求中用于分隔命令参数的逻辑使用 按空格拆分 的方式。
CVSS Information
N/A
Vulnerability Type
N/A