Описание
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
A flaw was found in simple-git. A remote attacker could exploit this vulnerability by providing specially crafted input to the options argument, bypassing a previous security fix. This incomplete fix allows an attacker to enable certain protocol extensions, which could lead to remote code execution.
Отчет
This Important flaw in the simple-git library allows for Remote Code Execution when untrusted input is passed to the options argument. An attacker could bypass a previous security fix by enabling specific protocol extensions, leading to arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | grafana | Will not fix | ||
| Red Hat Enterprise Linux 9 | grafana | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | simple-git | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | simple-git | Not affected | ||
| Red Hat Process Automation 7 | simple-git | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Уязвимость библиотеки simple-git программной платформы Node.js, позволяющая нарушителю изменить конфигурацию уязвимого программного обеспечения и выполнить произвольный код
EPSS
8.8 High
CVSS3