CVE-2020-15123 is a critical command injection vulnerability (CWE-78) in the codecov npm package, affecting versions prior to 3.7.1. An attacker could exploit this with low complexity via a network vector, potentially leading to high impact on confidentiality and integrity, though user interaction is required. Despite a CVSS score of 9.3, there is no evidence of active exploitation, public exploit code, or significant community discussion, and its EPSS score is very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.7.1CPE matchmatch criteria | cpe:2.3:a:codecov:codecov:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.