curlrequest allows execution of arbitrary commands
Critical severity
GitHub Reviewed
Published
May 13, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 12, 2020
Published to the GitHub Advisory Database
May 13, 2020
Last updated
Jan 9, 2023
curlrequest through 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands by using a semicolon char in any of the
options
values.References