Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxq4-c3j7-c5jv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

CVSS3: 7.5
nvd
почти 8 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

CVSS3: 7.5
debian
почти 8 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that ...

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-74