Medium severity6.5NVD Advisory· Published Jul 13, 2022· Updated Jun 17, 2026
CVE-2019-10800
CVE-2019-10800
Description
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codecovPyPI | < 2.0.16 | 2.0.16 |
Affected products
5- codecov/codecovdescription
- ghsa-coords3 versionspkg:pypi/codecovpkg:rpm/opensuse/python-codecov&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-codecov&distro=openSUSE%20Leap%2015.4
< 2.0.16+ 2 more
- (no CPE)range: < 2.0.16
- (no CPE)range: < 2.0.15-150100.3.3.1
- (no CPE)range: < 2.0.15-150100.3.3.1
Patches
Vulnerability mechanics
References
5- github.com/codecov/codecov-python/commit/2a80aa434f74feb31242b6f213b75ce63ae97902nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-PYTHON-CODECOV-552149nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h3qr-fjhm-jphwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10800ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/codecov/PYSEC-2022-238.yamlghsaWEB
News mentions
0No linked articles in our index yet.