Vulnerability Description
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Async-Git Project | Async-Git | < 1.13.2 |
Related Weaknesses (CWE)
References
- https://advisory.checkmarx.net/advisory/CX-2021-4772ExploitThird Party Advisory
- https://github.com/omrilotan/async-git/pull/13Third Party Advisory
- https://github.com/omrilotan/async-git/pull/13/commits/611823bd97dd41e9e8127c380PatchThird Party Advisory
- https://github.com/omrilotan/async-git/pull/13/commits/a5f45f58941006c4cc1699609PatchThird Party Advisory
- https://github.com/omrilotan/async-git/pull/14PatchThird Party Advisory
- https://advisory.checkmarx.net/advisory/CX-2021-4772ExploitThird Party Advisory
- https://github.com/omrilotan/async-git/pull/13Third Party Advisory
- https://github.com/omrilotan/async-git/pull/13/commits/611823bd97dd41e9e8127c380PatchThird Party Advisory
- https://github.com/omrilotan/async-git/pull/13/commits/a5f45f58941006c4cc1699609PatchThird Party Advisory
- https://github.com/omrilotan/async-git/pull/14PatchThird Party Advisory
FAQ
What is CVE-2021-3190?
CVE-2021-3190 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
How severe is CVE-2021-3190?
CVE-2021-3190 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3190?
Check the references section above for vendor advisories and patch information. Affected products include: Async-Git Project Async-Git.