Описание
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.
A flaw was found in Renovate. Attackers with repository write access can exploit a command injection vulnerability in the hermit manager. This occurs because user-provided dependency names are not properly sanitized when appended to install and uninstall commands. Successful exploitation allows an attacker to execute arbitrary commands on the machine running Renovate.
Отчет
This flaw has a MODERATE impact on Renovate. A command injection flaw in Renovate's hermit manager allowed a user with repository write access to execute arbitrary commands on the machine running Renovate by supplying a maliciously named dependency, which was appended to install/uninstall commands without sanitization. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0); the vulnerable hermit-manager code is not present in the shipped version, so Red Hat's product is not affected.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Ссылки на источники
Дополнительная информация
Статус:
6.7 Medium
CVSS3
Связанные уязвимости
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.
Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall commands without proper sanitization. Attackers with repository write access can provide maliciously named hermit dependencies to execute arbitrary commands on the machine running Renovate.
6.7 Medium
CVSS3