This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
References
https://nvd.nist.gov/vuln/detail/CVE-2020-7698
https://github.com/Gerapy/Gerapy/commit/e844…