Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g397-v4w5-4m79

Опубликовано: 02 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Command injection in cocoapods-downloader

The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Пакеты

Наименование

cocoapods-downloader

rubygems
Затронутые версииВерсия исправления

< 1.6.2

1.6.2

EPSS

Процентиль: 73%
0.00753
Низкий

8.1 High

CVSS3

Дефекты

CWE-74
CWE-88

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

EPSS

Процентиль: 73%
0.00753
Низкий

8.1 High

CVSS3

Дефекты

CWE-74
CWE-88