Логотип exploitDog
bind:CVE-2022-24433
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24433

Количество 2

Количество 2

nvd логотип

CVE-2022-24433

почти 4 года назад

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f95-r44v-8mrg

почти 4 года назад

Command injection in simple-git

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24433

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3f95-r44v-8mrg

Command injection in simple-git

CVSS3: 8.1
1%
Низкий
почти 4 года назад

Уязвимостей на страницу