Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS04am13LXdqcjgtMng2Ns4AAtFK

Command injection in git-clone

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

Credits

Credit to @lirantal for discovering this vulnerability.

Permalink: https://github.com/advisories/GHSA-8jmw-wjr8-2x66
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04am13LXdqcjgtMng2Ns4AAtFK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 8 months ago


CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-8jmw-wjr8-2x66, CVE-2022-25900
References: Repository: https://github.com/jaz303/git-clone
Blast Radius: 32.4

Affected Packages

npm:git-clone
Dependent packages: 1,003
Dependent repositories: 10,041
Downloads: 594,668 last month
Affected Version Ranges: <= 0.2.0
No known fixed version
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0, 0.2.0