Количество 2
Количество 2
CVE-2022-21223
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
GHSA-g397-v4w5-4m79
Command injection in cocoapods-downloader
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-21223 The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. | CVSS3: 8.1 | 1% Низкий | почти 4 года назад | |
GHSA-g397-v4w5-4m79 Command injection in cocoapods-downloader | CVSS3: 8.1 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу