← Back

Blamer

blamer

Vendor: Blamer Project • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Blamer Project
1Blamer
Nov 21, 2024
Sep 19, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific sc...Show more
Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.Show less
1Blamer Project
1Blamer
Nov 21, 2024
Mar 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
1Blamer Project
1Blamer
Nov 21, 2024
Mar 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.