CVE-2022-24437
Summary
| CVE | CVE-2022-24437 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-01 16:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection. |
Risk And Classification
Problem Types: CWE-88
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Git-pull-or-clone Project | Git-pull-or-clone | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: fix command injection vector · feross/git-pull-or-clone@f9ce092 · GitHub | MISC | github.com | |
| Command Injection vulnerability in [email protected] · GitHub | MISC | gist.github.com | |
| Command Injection in git-pull-or-clone | CVE-2022-24437 | Snyk | MISC | snyk.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Liran Tal of Snyk
There are currently no legacy QID mappings associated with this CVE.