CVE-2022-25865
Published on: Not Yet Published
Last Modified on: 05/13/2022 09:15:00 PM UTC
The following vulnerability was found:
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
- CVE-2022-25865 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Fix git fetch - addresses a potential security concern regarding git fetch by kenotron · Pull Request #103 · microsoft/workspace-tools · GitHub | github.com text/html |
![]() |
Command Injection in workspace-tools | CVE-2022-25865 | Snyk | snyk.io text/html |
![]() |
Fix git fetch - addresses a potential security concern regarding git … · microsoft/[email protected] · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
Discovery Credit
Alessio Della Libera of Snyk Research Team
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-25865 : The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument inj… twitter.com/i/web/status/1… | 2022-05-13 20:06:54 |
![]() |
Potentially Critical CVE Detected! CVE-2022-25865 The package workspace-tools before 0.18.4 are vulnerable to Comma… twitter.com/i/web/status/1… | 2022-05-13 20:56:02 |
![]() |
Git - CVE-2022-25865: github.com/microsoft/work… | 2022-05-13 23:04:06 |
![]() |
CVE-2022-25865 | 2022-05-13 20:38:19 |