Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-h3qr-fjhm-jphw: Codecov prior to 2.0.16 does not sanitize gcov arguments

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

ghsa
#vulnerability#git

Codecov prior to 2.0.16 does not sanitize gcov arguments

Moderate severity GitHub Reviewed Published Jul 14, 2022 • Updated Jul 15, 2022

Related news

CVE-2019-10800: Snyk Vulnerability Database | Snyk

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.