Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4q6-9qm4-h8j4

Опубликовано: 09 июн. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

OS Command Injection in cookiecutter

The package cookiecutter before 2.1.1 is vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Пакеты

Наименование

cookiecutter

pip
Затронутые версииВерсия исправления

< 2.1.1

2.1.1

EPSS

Процентиль: 82%
0.01775
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
nvd
больше 3 лет назад

The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
debian
больше 3 лет назад

The package cookiecutter before 2.1.1 are vulnerable to Command Inject ...

EPSS

Процентиль: 82%
0.01775
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-78