The vendor explicitly states that these products are not affected by this CVE.
- All currently supported Red Hat products
- Summary
- A flaw was found in Renovate. This command injection vulnerability exists within the gleam manager, where the 'depName' parameter is not properly sanitized when appended to 'gleam deps update' commands. An attacker with repository write access can exploit this by crafting malicious 'gleam.toml' files, leading to the execution of arbitrary commands on the system running Renovate.
- Remediation
- No remediation text is recorded.
