ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28490”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28490
Published
2021-02-18
CVSS:
9.1
ShadowTrackr CVSS:
6.9
Summary:
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')