CVE-2022-24066

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2022
Last modified:
08/08/2023

Description

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* 3.5.0 (excluding)