CVE-2020-7712
ADVISORY - githubSummary
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Common Weakness Enumeration (CWE)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
NIST
1.2
CVSS SCORE
7.2highGitHub
1.2
CVSS SCORE
7.2highChainguard
CGA-2p2j-g87h-g5xm
-
Chainguard
CGA-345v-hqm5-8xrc
-
Chainguard
CGA-3mfg-wvqc-fpmg
-
Chainguard
CGA-5qqf-7w63-hx25
-
Chainguard
CGA-5w76-g2h7-gxrp
-
Chainguard
CGA-622m-m68m-7ggq
-
Chainguard
CGA-6wg9-3j64-f8wj
-
Chainguard
CGA-7w42-m96m-c6jg
-
Chainguard
CGA-8x6f-5w3r-h5hx
-
Chainguard
CGA-947x-3r27-rcjq
-
Chainguard
CGA-96gq-cggr-xh2v
-
Chainguard
CGA-9vv8-g8g6-h76r
-
Chainguard
CGA-c2h3-p9mm-56pm
-
Chainguard
CGA-chrj-hf73-6gf5
-
Chainguard
CGA-f2q9-8842-vm8g
-
Chainguard
CGA-f5qr-9999-86h9
-
Chainguard
CGA-ff8p-vfgp-36cm
-
Chainguard
CGA-fr86-hr4c-qvg8
-
Chainguard
CGA-g6c8-5r48-v6hg
-
Chainguard
CGA-jm34-5hmg-4xx4
-
Chainguard
CGA-jpcr-3whf-m9hc
-
Chainguard
CGA-jww8-jxrp-m42q
-
Chainguard
CGA-pjc4-r353-rg95
-
Chainguard
CGA-q2r2-7hj8-6whg
-
Chainguard
CGA-qvg8-h36r-f4rv
-
Chainguard
CGA-v244-5j7g-jw4g
-
Chainguard
CGA-v6c5-q8jg-5686
-
Chainguard
CGA-whp3-jj96-vvc2
-
Chainguard
CGA-wqhc-6326-7f2r
-
Chainguard
CGA-wqqg-fvhq-hcg7
-
intheWild
-
-