VYPR

Grafanaplugin

by Taosdata

CVEs (1)

  • CVE-2023-34111HigJun 6, 2023
    risk 0.53cvss 8.1epss 0.04

    The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure usage of `${{ github.event.pull_request.title }}` in a bash…