CVE-2021-44685
Summary
| CVE | CVE-2021-44685 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-07 00:15:00 UTC |
| Updated | 2021-12-08 13:13:00 UTC |
| Description | Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution). |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Git-it Project | Git-it | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases · jlord/git-it-electron · GitHub | MISC | github.com | |
| OS Command Injection in Git-it · Issue #3 · dwisiswant0/advisory · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.