CVE-2017-1000451

UnknownEPSS 0.77%

Last modified

CVE-2017-1000451 is a vulnerability of currently unknown severity. fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.

Description

fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.

Metrics

EPSS Probability
0.77%

51.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Fs-Git ProjectFs-Git<= 1.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-1000451?
fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
How severe is CVE-2017-1000451?
Severity scoring for CVE-2017-1000451 is pending analysis. The EPSS model estimates a 0.77% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1000451?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-1000451?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST