CVE-2020-15123
Last modified
CVE-2020-15123 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. EPSS estimates a 3.81% chance of exploitation in the next 30 days.
Description
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix was incomplete. It only blocked &, and command injection is still possible using backticks instead to bypass the sanitizer. The attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Codecov | Codecov | < 3.7.1 |
References
- https://github.com/advisories/GHSA-5q88-cjfq-g2mhThird Party Advisory
- https://github.com/codecov/codecov-node/commit/c0711c656686e902af2cd92d6aecc8074de4d83dPatch, Third Party Advisory
- https://github.com/codecov/codecov-node/pull/180Third Party Advisory
- https://github.com/codecov/codecov-node/security/advisories/GHSA-xp63-6vf5-xf3vThird Party Advisory
- https://lgtm.com/query/7714424068617023832Exploit, Third Party Advisory
- https://github.com/advisories/GHSA-5q88-cjfq-g2mhThird Party Advisory
- https://github.com/codecov/codecov-node/commit/c0711c656686e902af2cd92d6aecc8074de4d83dPatch, Third Party Advisory
- https://github.com/codecov/codecov-node/pull/180Third Party Advisory
- https://github.com/codecov/codecov-node/security/advisories/GHSA-xp63-6vf5-xf3vThird Party Advisory
- https://lgtm.com/query/7714424068617023832Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15123?
How severe is CVE-2020-15123?
How do I fix CVE-2020-15123?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15117In Synergy before version 1.12.0, a Synergy server can be cr…6.5
- CVE-2020-15118In Wagtail before versions 2.7.4 and 2.9.3, when a form page…5.4
- CVE-2020-15119In auth0-lock versions before and including 11.25.1, dangero…5.4
- CVE-2020-1512An information disclosure vulnerability exists when the Wind…7.8
- CVE-2020-15120In "I hate money" before version 4.1.5, an authenticated mem…4.9
- CVE-2020-15121In radare2 before version 4.5.0, malformed PDB file names in…9.6
- CVE-2020-15124In Goobi Viewer Core before version 4.8.3, a path traversal …6.5
- CVE-2020-15125In auth0 (npm package) versions before 2.27.1, a DenyList of…7.7
- CVE-2020-15126In parser-server from version 3.5.0 and before 4.3.0, an aut…6.5
- CVE-2020-15127In Contour ( Ingress controller for Kubernetes) before versi…7.5
- CVE-2020-15128In OctoberCMS before version 1.0.468, encrypted cookie value…6.3
- CVE-2020-15129In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, the…4.7
Are you affected by CVE-2020-15123?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
