chore(deps): update dependency codecov to v3.7.1 [security]#675
chore(deps): update dependency codecov to v3.7.1 [security]#675renovate[bot] wants to merge 1 commit into
Conversation
Generated by 🚫 dangerJS |
Codecov ReportBase: 83.77% // Head: 83.77% // No change to project coverage 👍
Additional details and impacted files@@ Coverage Diff @@
## master #675 +/- ##
=======================================
Coverage 83.77% 83.77%
=======================================
Files 326 326
Lines 2694 2694
Branches 174 174
=======================================
Hits 2257 2257
Misses 372 372
Partials 65 65 Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here. ☔ View full report at Codecov. |
|
Deploy preview for mcs-lite-introduction ready! Built with commit 0563eb2 https://deploy-preview-675--mcs-lite-introduction.netlify.app |
|
Deploy preview for mcslite ready! Built with commit 0563eb2 |
|
Deploy preview for mcs-lite-ui ready! Built with commit 0563eb2 |
f0db7f2 to
0563eb2
Compare
0563eb2 to
f0bf73e
Compare
f0bf73e to
fb85e41
Compare
fb85e41 to
752183e
Compare
752183e to
f1d8642
Compare
f1d8642 to
cab570b
Compare
This PR contains the following updates:
3.0.2→3.7.1codecov NPM module allows remote attackers to execute arbitrary commands
CVE-2020-7597 / GHSA-5q88-cjfq-g2mh
More information
Details
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Command injection in codecov (npm package)
CVE-2020-15123 / GHSA-xp63-6vf5-xf3v
More information
Details
Impact
The
uploadmethod has a command injection vulnerability. Clients of thecodecov-nodelibrary are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.A similar CVE was issued: CVE-2020-7597, but the fix was incomplete. It only blocked
&, and command injection is still possible using backticks instead to bypass the sanitizer.We have written a CodeQL query, which automatically detects this vulnerability. You can see the results of the query on the
codecov-nodeproject here.Patches
This has been patched in version 3.7.1
Workarounds
None, however, the attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.
References
For more information
If you have any questions or comments about this advisory:
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
codecov/codecov-node (codecov)
v3.7.1Compare Source
v3.7.0Compare Source
v3.6.5Compare Source
v3.6.4Compare Source
v3.6.3Compare Source
v3.6.2Compare Source
v3.6.1Compare Source
v3.6.0Compare Source
v3.5.0Compare Source
v3.4.0Compare Source
v3.3.0Compare Source
--pipe,-lv3.2.0Compare Source
.
v3.1.0Compare Source
v3.0.4Compare Source
v3.0.3Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.