Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf6w-45cf-qhmp

Опубликовано: 15 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Git-fastclone passes user modifiable strings directly to a shell command

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to cd and git clone commands in the library.

Пакеты

Наименование

git-fastclone

rubygems
Затронутые версииВерсия исправления

< 1.0.5

1.0.5

EPSS

Процентиль: 85%
0.02489
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
больше 9 лет назад

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.

EPSS

Процентиль: 85%
0.02489
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77