An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS04am13LXdqcjgtMng2Ns4AAtFK

Command injection in git-clone

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.


Credit to @lirantal for discovering this vulnerability.

Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 8 months ago

CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-8jmw-wjr8-2x66, CVE-2022-25900
References: Repository:
Blast Radius: 32.4

Affected Packages

Dependent packages: 1,003
Dependent repositories: 10,041
Downloads: 594,668 last month
Affected Version Ranges: <= 0.2.0
No known fixed version
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0, 0.2.0