CRITICAL

CVE-2019-5485

CVSS v3

10

CRITICAL

EPSS Score

49.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

Technical details

Published
9/13/2019

Frequently asked questions

What is CVE-2019-5485?

NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

Is CVE-2019-5485 actively exploited?

Active exploitation of CVE-2019-5485 has not been confirmed. The EPSS score is 49.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-5485?

CVE-2019-5485 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2019-5485 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.