VDB
CVE-2019-10800
CVE-2019-10800
PUBLISHED
CVSS 7.099999904632568 HIGH
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
EPSS 1.15% · 64.7th percentile
Risk Scores
CVSS 4.0
7.099999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
1.15%
64.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | codecov | unspecified |
| PyPI | codecov | 0 |
| codecov | codecov-python | 0 |
Timeline
- Jul 13, 2022 CVE Published
- Jul 23, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Oct 25, 2022 EPSS Score
- Dec 11, 2022 EPSS Score
- Jan 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 15, 2023 EPSS Score
- May 1, 2023 EPSS Score
- Aug 3, 2023 EPSS Score
- Sep 19, 2023 EPSS Score
- Nov 5, 2023 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10800 advisory
- https://github.com/advisories/GHSA-h3qr-fjhm-jphw advisory
- https://github.com/codecov/codecov-python package
- https://github.com/pypa/advisory-database/tree/main/vulns/codecov/PYSEC-2022-238.yaml url
- https://github.com/codecov/codecov-python/commit/2a80aa434f74feb31242b6f213b75ce63ae97902 patch
- https://snyk.io/vuln/SNYK-PYTHON-CODECOV-552149 exploit