First published: Wed Sep 02 2020(Updated: )
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Erlang Rebar3 | >=3.1.0<=3.13.2 | |
Erlang Rebar3 | =3.0.0-beta3 | |
Erlang Rebar3 | =3.0.0-beta4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13802 is classified as a high severity vulnerability due to its potential for OS command injection.
To fix CVE-2020-13802, upgrade Rebar3 to version 3.13.3 or later.
Rebar3 versions from 3.0.0-beta.3 to 3.13.2 are affected by CVE-2020-13802.
CVE-2020-13802 is an OS command injection vulnerability.
The impact of CVE-2020-13802 can allow an attacker to execute arbitrary commands on the affected system.