The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837).
The fetch module was susceptible to path traversal (CVE-2019-3828).
{ "section": "core" }