CVE-2021-23420: Deserialization of Untrusted Data
(updated )
The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
References
Detect and mitigate CVE-2021-23420 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →