CVE-2022-20001
Summary
| CVE | CVE-2022-20001 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-14 19:15:00 UTC |
| Updated | 2023-11-07 03:42:00 UTC |
| Description | fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: fish-3.4.1-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| fish_git_prompt: be careful about git config by ridiculousfish · Pull Request #8589 · fish-shell/fish-shell · GitHub |
MISC |
github.com |
|
| Navigating to a compromised git repository may lead to arbitrary code exection · Advisory · fish-shell/fish-shell · GitHub |
CONFIRM |
github.com |
|
| Debian -- Security Information -- DSA-5234-1 fish |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 35 Update: fish-3.4.1-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: fish-3.4.1-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fish: User-assisted execution of arbitrary code (GLSA 202309-10) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 36 Update: fish-3.4.1-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Release fish 3.4.0 (released March 12, 2022) · fish-shell/fish-shell · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181067 Debian Security Update for fish (DSA 5234-1)
- 182002 Debian Security Update for fish (CVE-2022-20001)
- 282555 Fedora Security Update for fish (FEDORA-2022-cd2c5e0634)
- 354349 Amazon Linux Security Advisory for fish : ALAS2022-2022-056
- 502216 Alpine Linux Security Update for fish
- 503923 Alpine Linux Security Update for fish
- 691033 Free Berkeley Software Distribution (FreeBSD) Security Update for shells/fish (a3b10c9b-99d9-11ed-aa55-d05099fed512)
- 710755 Gentoo Linux Fish User-assisted execution of arbitrary code Vulnerability (GLSA 202309-10)
- 901092 Common Base Linux Mariner (CBL-Mariner) Security Update for fish (9070)