RULE(RULE ID:333368)

Rule General Information
Release Date: 2021-04-01
Rule Name: NPMJS gitlabhook Remote Command Execution Vulnerability (CVE-2019-5485)
Severity:
CVE ID:
Rule Protection Details
Description: NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/154598/NPMJS-gitlabhook-0.0.17-Remote-Command-Execution.html
https://hackerone.com/reports/685447
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://github.com/rolfn/node-gitlab-hook