CVE-2021-3190: OS Command Injection
(updated )
The async-git package for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset
and git.tag
.
References
Detect and mitigate CVE-2021-3190 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →