Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25648

Опубликовано: 13 апр. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

A flaw was found in ruby-git, where the package is vulnerable to command injection via the git argument. This flaw allows an attacker to set additional flags, which leads to performing command injections.

Отчет

Red Hat Satellite 10 is marked as affected, as it is shipping the vulnerable code. However, the dependency is not used within the product as such, so the impact is considered as moderate. Other Red Hat Satellite versions are not delivering this dependency, so they are not vulnerable or affected at all.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2076843ruby-git: package vulnerable to Command Injection via git argument injection

EPSS

Процентиль: 91%
0.04871
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 4 лет назад

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
nvd
больше 4 лет назад

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 8.1
debian
больше 4 лет назад

The package git before 1.11.0 are vulnerable to Command Injection via ...

CVSS3: 9.8
github
больше 4 лет назад

Command injection in ruby-git

CVSS3: 8.1
fstec
больше 4 лет назад

Уязвимость библиотеки Ruby/Git интерпретатора Ruby, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 91%
0.04871
Низкий

9.8 Critical

CVSS3