GHSA-49q3-8867-5wmp
Dashboard / Vulnerabilities / GHSA-49q3-8867-5wmp
Summary: Remote Command Execution in reg-keygen-git-hash-plugin
Details: ### Impact `reg-keygen-git-hash-plugin` through 0.10.15 allow remote attackers to execute of arbitrary commands. ### Patches Upgrade to version 0.10.16 or later. ### For more information If you have any questions or comments about this advisory: - Open an issue in [reg-viz/reg-suit](https://github.com/reg-viz/reg-suit)
References: https://github.com/reg-viz/reg-suit/security/advisories/GHSA-49q3-8867-5wmp, https://nvd.nist.gov/vuln/detail/CVE-2021-32673, https://github.com/reg-viz/reg-suit/commit/f84ad9c7a22144d6c147dc175c52756c0f444d87, https://github.com/reg-viz/reg-suit/releases/tag/v0.10.16, https://www.npmjs.com/package/reg-keygen-git-hash-plugin
Affected packages
Package
Name: reg-keygen-git-hash-plugin
Purl: pkg:npm/reg-keygen-git-hash-plugin
Affected ranges
Type: SEMVER
Events:
