Junglewise Threat Intelligence

CVE-2020-28430: nuance-gulp-build-common command injection

CVE-2020-28430 · Severity: low · CVSS 3.1 · Published 2021-04-13

Vendors: npm.

Executive brief

nuance-gulp-build-common is a build utility library used in development pipelines. A command injection vulnerability allows attackers to execute arbitrary system commands through the library's run() method, potentially compromising build environments and enabling malware injection into built artifacts.

Technical details

The vulnerability is a command injection flaw in the index.js file of nuance-gulp-build-common, where the run() function fails to properly sanitize or escape shell metacharacters in its input. An attacker who can invoke the run() function with attacker-controlled input can execute arbitrary OS commands via shell interpretation (CWE-78). Exploitation requires direct code execution within the application that uses the library. The advisory was withdrawn in August 2021, with Snyk later noting "this was deemed not a vulnerability" and clarifying it "doesn't affect any version of package nuance-gulp-build-common," suggesting potential disputes around impact assessment or affected scope.

Affected products

  • npm nuance-gulp-build-common all versions including 0.0.1

Timeline

  • 2020-12-11: disclosed
  • 2021-02-23: advisory: NVD publication
  • 2021-08-30: other: Advisory withdrawn

References