Rebar3: Command Injection A vulnerability has been discovered in Rebar3, which can lead to command injection. rebar-bin 2024-05-12 2024-05-12 749363 local 3.14.4 3.14.4

A sophisticated build-tool for Erlang projects that follows OTP principles.

Rebar3 is vulnerable to OS command injection via the URL parameter of a dependency specification.

A vulnerability has been discovered in Rebar3. Please review the CVE identifier referenced below for details.

There is no known workaround at this time.

Gentoo has discontinued support for Rebar3 binary package. We recommend that users unmerge it:

# emerge --ask --depclean "dev-util/rebar-bin"
CVE-2020-13802 graaff graaff