Логотип exploitDog
bind:CVE-2022-40764
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-40764

Количество 3

Количество 3

redhat логотип

CVE-2022-40764

больше 3 лет назад

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-40764

больше 3 лет назад

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-hpqj-7cj6-hfj8

больше 3 лет назад

Snyk CLI affected by Command Injection vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-40764

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-40764

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-hpqj-7cj6-hfj8

Snyk CLI affected by Command Injection vulnerability

CVSS3: 7.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу