CVE-2019-10800

Description

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.317

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10800 are fixed in Python-codecov 2.0.16Windows
Vulnerabilities CVE-2019-10800 are fixed in Python-codecov for linux 2.0.16Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234