logo

Vulnerability details for CVE-2020-8149 

Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

CVSS Score (Vector) 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
ThreatWorx Rating 4 - Critical
Weakness Types Improper Control of Generation of Code ('Code Injection'), Code Execution, Code Injection
Reported By Open Source, GitHub, CNNVD
First Reported May 09, 2020 by Open Source
Last Updated Jun 12, 2020 by GitHub
NVD Status Published CVE-2020-8149
Affected Products 6 affected product(s) reported by NVD, Open Source, GitHub, CNNVD
Patches 1 patch(es) published by CNNVD
Remediations 2 remediation(s) published by GitHub, Open Source
Latest Reference GitHub