Safety vulnerability ID: 37934
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Codecov 2.0.16 includes a fix for CVE-2019-10800: Remote code execution. The vulnerability exists due to improper sanitization of "gcov" arguments before being provided to the "popen" method. A remote authenticated attacker can execute arbitrary OS commands on the target system.
Latest version: 2.1.13
Hosted coverage reports for GitHub, Bitbucket and Gitlab
- fixed reported command injection vulnerability.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application