CVE-2020-7646: curlrequest allows execution of arbitrary commands
(updated )
curlrequest through 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands by using a semicolon char in any of the options values.
References
Code Behaviors & Features
Detect and mitigate CVE-2020-7646 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →