Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22370
HistoryJan 28, 2020 - 2:31 a.m.

OS Command Injection

2020-01-2802:31:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.006 Low

EPSS

Percentile

79.1%

codecov is vulnerable to OS command injection. Lack of validation and sanitization of the gcov-args allows an attacker to inject and execute arbitrary OS commands on the system.

CPENameOperatorVersion
codecovle3.6.1

0.006 Low

EPSS

Percentile

79.1%