Lucene search

K
cvelistMitreCVELIST:CVE-2018-25083
HistoryMar 27, 2023 - 12:00 a.m.

CVE-2018-25083

2023-03-2700:00:00
mitre
www.cve.org
5
cve-2018-25083
pullit package
node.js
os command injection
git branch name

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

57.8%

The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

57.8%

Related for CVELIST:CVE-2018-25083