Описание
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.16.0 (исключая)
cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 97%
0.41312
Средний
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-94
NVD-CWE-noinfo
CWE-78
Связанные уязвимости
EPSS
Процентиль: 97%
0.41312
Средний
8.1 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-94
NVD-CWE-noinfo
CWE-78