Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3x62-x456-q2vm

Опубликовано: 03 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

OS Command Injection in git-pull-or-clone

The package git-pull-or-clone before 2.0.2 is vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

Credits

Credit @lirantal for discovering this vulnerability.

Пакеты

Наименование

git-pull-or-clone

npm
Затронутые версииВерсия исправления

< 2.0.2

2.0.2

EPSS

Процентиль: 93%
0.10388
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

EPSS

Процентиль: 93%
0.10388
Средний

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-78