VDB

CVE-2019-10800

CVE-2019-10800 PUBLISHED CVSS 7.099999904632568 HIGH

This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.

EPSS 1.15% · 64.7th percentile

Risk Scores

CVSS 4.0
7.099999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
1.15%
64.7th percentile

Affected Products

VendorProductVersions
n/acodecovunspecified
PyPIcodecov0
codecovcodecov-python0

Timeline

  • Jul 13, 2022 CVE Published
  • Jul 23, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Oct 25, 2022 EPSS Score
  • Dec 11, 2022 EPSS Score
  • Jan 27, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
  • May 1, 2023 EPSS Score
  • Aug 3, 2023 EPSS Score
  • Sep 19, 2023 EPSS Score
  • Nov 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›