Headline
GHSA-h3qr-fjhm-jphw: Codecov prior to 2.0.16 does not sanitize gcov arguments
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
Codecov prior to 2.0.16 does not sanitize gcov arguments
Moderate severity GitHub Reviewed Published Jul 14, 2022 • Updated Jul 15, 2022
Related news
CVE-2019-10800: Snyk Vulnerability Database | Snyk
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.