将我的项目更新到 Angular 8.0.3 后,我的 github 警报上出现此错误。
这是一个没有补救措施的漏洞。
没有可用的补丁版本。
Shelljs 0.8.3 and before are vulnerable to Command Injection.
Commands can be invoked from shell.exec(),
those commands will include input from external sources,
to be passed as arguments to system executables
and allowing an attacker to inject arbitrary commands.
有人有这方面的任何信息吗?