CVE-2020-7596: OS Command Injection
Published Jan 25, 2020
·Updated
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
Affected Software
1 affected component
Codecov Nodejs Uploader Node.js<3.6.2
Remediation
Patch Available
Event History
Jan 25, 2020
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7596?
CVE-2020-7596 has a high severity level due to the potential for remote command execution.
2
How do I fix CVE-2020-7596?
To fix CVE-2020-7596, upgrade the Codecov npm module to version 3.6.2 or later.
3
What kind of attacks can exploit CVE-2020-7596?
CVE-2020-7596 can be exploited to execute arbitrary commands remotely by manipulating the 'gcov-args' argument.
4
Which versions of the Codecov npm module are affected by CVE-2020-7596?
All versions of the Codecov npm module before 3.6.2 are affected by CVE-2020-7596.
5
Is CVE-2020-7596 related to Codecov's functionality?
Yes, CVE-2020-7596 directly affects the Codecov npm module's command handling capabilities.