Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04am13LXdqcjgtMng2Ns4AAtFK
Command injection in git-clone
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack
feature of git.
Credits
Credit to @lirantal for discovering this vulnerability.
Permalink: https://github.com/advisories/GHSA-8jmw-wjr8-2x66JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04am13LXdqcjgtMng2Ns4AAtFK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: 11 months ago
CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-8jmw-wjr8-2x66, CVE-2022-25900
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-25900
- https://gist.github.com/lirantal/9441f3a1212728476f7a6caa4acb2ccc
- https://snyk.io/vuln/SNYK-JS-GITCLONE-2434308
- https://github.com/jaz303/git-clone/commit/fd330459593aef7c7a8c54d786e3c4d5722749f9
- https://github.com/advisories/GHSA-8jmw-wjr8-2x66
Blast Radius: 32.4
Affected Packages
npm:git-clone
Dependent packages: 1,003Dependent repositories: 10,041
Downloads: 592,463 last month
Affected Version Ranges: <= 0.2.0
No known fixed version
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0, 0.2.0