CVE-2022-24066 – simple-git
Package
Manager: npm
Name: simple-git
Vulnerable Version: >=0 <3.5.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.02492 pctl0.8475
Details
Command injection in simple-git `simple-git` (maintained as [git-js](https://github.com/steveukx/git-js) named repository on GitHub) is a light weight interface for running git commands in any node.js application.The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover. A fix was released in simple-git@3.5.0.
Metadata
Created: 2022-04-02T00:00:13Z
Modified: 2022-10-13T15:14:51Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-28xr-mwxg-3qc8/GHSA-28xr-mwxg-3qc8.json
CWE IDs: ["CWE-88"]
Alternative ID: GHSA-28xr-mwxg-3qc8
Finding: F014
Auto approve: 1