CVE-2021-41088: Exposure of Resource to Wrong Sphere
(updated )
Elvish is a programming language and interactive shell, combined into one package. Elvish’s web UI backend (started by elvish -web
) hosts an endpoint that allows executing the code sent from the web UI.
References
Detect and mitigate CVE-2021-41088 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →