Command injection in Gerapy
Critical severity
GitHub Reviewed
Published
May 6, 2021
to the GitHub Advisory Database
•
Updated Sep 20, 2024
Description
Published by the National Vulnerability Database
Jul 29, 2020
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
May 6, 2021
Last updated
Sep 20, 2024
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
References