Логотип exploitDog
bind:CVE-2024-21533
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21533

Количество 2

Количество 2

nvd логотип

CVE-2024-21533

больше 1 года назад

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL scheme, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pr45-cg4x-ff4m

больше 1 года назад

ggit is vulnerable to Arbitrary Argument Injection via the clone() API

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21533

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and the file on disk to clone to. The library does not sanitize for user input or validate a given URL scheme, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-pr45-cg4x-ff4m

ggit is vulnerable to Arbitrary Argument Injection via the clone() API

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу