CVE-2020-7738: Code Injection
(updated )
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load()
of the package js-yaml instead of its secure replacement, safeLoad()
.
References
Detect and mitigate CVE-2020-7738 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →