Description
Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qffw-8wg7-h665 | Command injection in git-interface |
References
History
No history.
Status: PUBLISHED
Assigner: @huntrdev
Published:
Updated: 2024-08-03T00:03:06.306Z
Reserved: 2022-04-22T00:00:00.000Z
Link: CVE-2022-1440
No data.
Status : Modified
Published: 2022-04-22T18:15:07.917
Modified: 2024-11-21T06:40:44.490
Link: CVE-2022-1440
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA