Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25648

Опубликовано: 13 апр. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

A flaw was found in ruby-git, where the package is vulnerable to command injection via the git argument. This flaw allows an attacker to set additional flags, which leads to performing command injections.

Отчет

Red Hat Satellite 10 is marked as affected, as it is shipping the vulnerable code. However, the dependency is not used within the product as such, so the impact is considered as moderate. Other Red Hat Satellite versions are not delivering this dependency, so they are not vulnerable or affected at all.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2076843ruby-git: package vulnerable to Command Injection via git argument injection

EPSS

Процентиль: 81%
0.01499
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
nvd
почти 4 года назад

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
debian
почти 4 года назад

The package git before 1.11.0 are vulnerable to Command Injection via ...

CVSS3: 9.8
github
почти 4 года назад

Command injection in ruby-git

CVSS3: 8.1
fstec
почти 4 года назад

Уязвимость библиотеки Ruby/Git интерпретатора Ruby, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 81%
0.01499
Низкий

9.8 Critical

CVSS3