codecov records
4 published records for vendor codecov.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2020-15123No exploit | Command injection in codecov (npm package)codecov · codecov · CWE-78 | Critical9.3 | — | 3.8% | Jul 20, 2020 |
36Monitor | CVE-2020-7597No exploit | codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argumcodecov · codecov · CWE-78 | High8.8 | — | 2.9% | Feb 17, 2020 |
36Monitor | CVE-2020-7596No exploit | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.codecov · nodejs uploader · CWE-78 | High8.8 | — | 1.9% | Jan 25, 2020 |
26Monitor | CVE-2019-10800No exploit | This affects the package codecov before 2.0.16.codecov · codecov-python · CWE-88 | Medium6.5 | — | 1.2% | Jul 13, 2022 |
- CVE-2020-1512338Monitor
Command injection in codecov (npm package)
CriticalCVSS 9.3No exploitEPSS 4%codecov · codecovJul 20, 2020
- CVE-2020-759736Monitor
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argum
HighCVSS 8.8No exploitEPSS 3%codecov · codecovFeb 17, 2020
- CVE-2020-759636Monitor
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
HighCVSS 8.8No exploitEPSS 2%codecov · nodejs uploaderJan 25, 2020
- CVE-2019-1080026Monitor
This affects the package codecov before 2.0.16.
MediumCVSS 6.5No exploitEPSS 1%codecov · codecov-pythonJul 13, 2022