Количество 2
Количество 2
CVE-2022-25866
The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
GHSA-3xpw-vhmv-cw7h
Command injection in czproject/git-php
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-25866 The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. | CVSS3: 8.1 | 2% Низкий | почти 4 года назад | |
GHSA-3xpw-vhmv-cw7h Command injection in czproject/git-php | CVSS3: 8.1 | 2% Низкий | почти 4 года назад |
Уязвимостей на страницу