HIGH8.8
GHSA-49q3-8867-5wmp
Remote Command Execution in reg-keygen-git-hash-plugin
Quick fix
GHSA-49q3-8867-5wmp — reg-keygen-git-hash-plugin: upgrade to the fixed version with the command below.
npm install reg-keygen-git-hash-plugin@0.10.16Details
### Impact
`reg-keygen-git-hash-plugin` through 0.10.15 allow remote attackers to execute of arbitrary commands.
### Patches
Upgrade to version 0.10.16 or later.
### For more information
If you have any questions or comments about this advisory: - Open an issue in [reg-viz/reg-suit](https://github.com/reg-viz/reg-suit)
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/reg-keygen-git-hash-plugin
Introduced in:
0Fixed in: 0.10.16Fix
npm install reg-keygen-git-hash-plugin@0.10.16References
- https://github.com/reg-viz/reg-suit/security/advisories/GHSA-49q3-8867-5wmp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-32673[ADVISORY]
- https://github.com/reg-viz/reg-suit/commit/f84ad9c7a22144d6c147dc175c52756c0f444d87[WEB]
- https://github.com/reg-viz/reg-suit/releases/tag/v0.10.16[WEB]
- https://www.npmjs.com/package/reg-keygen-git-hash-plugin[WEB]