Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2022-24433

больше 4 лет назад

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f95-r44v-8mrg

больше 4 лет назад

Command injection in simple-git

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24433

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution.

CVSS3: 8.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3f95-r44v-8mrg

Command injection in simple-git

CVSS3: 8.1
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу