CVE-2020-26222
Summary
| CVE | CVE-2020-26222 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-13 16:15:00 UTC |
| Updated | 2020-12-03 15:53:00 UTC |
| Description | Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Dependabot-Core from version 0.119.0.beta1 before version 0.125.1, there is a remote code execution vulnerability in dependabot-common and dependabot-go_modules when a source branch name contains malicious injectable bash code. For example, if Dependabot is configured to use the following source branch name: "/$({curl,127.0.0.1})", Dependabot will make a HTTP request to the following URL: 127.0.0.1 when cloning the source repository. The fix was applied to version 0.125.1. As a workaround, one can escape the branch name prior to passing it to the Dependabot::Source class. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dependabot Project | Dependabot | All | All | All | All |
| Application | Dependabot Project | Dependabot | 0.119.0 | - | All | All |
| Application | Dependabot Project | Dependabot | 0.119.0 | beta1 | All | All |
| Application | Dependabot Project | Dependabot | All | All | All | All |
| Application | Dependabot Project | Dependabot | 0.119.0 | - | All | All |
| Application | Dependabot Project | Dependabot | 0.119.0 | beta1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| v0.125.1 by feelepxyz · Pull Request #2727 · dependabot/dependabot-core · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Remote code execution in dependabot-core branch names when cloning · Advisory · dependabot/dependabot-core · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| Merge pull request #2727 from dependabot/v0.125.1-release-notes · dependabot/dependabot-core@e089116 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.