The status, reinstall and remove commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.
2.2.24 for 2.2 LTS or 2.7.7 for mainline
Avoid installing dependencies via git by using --prefer-dist or the preferred-install: dist config setting.
{
"nvd_published_at": "2024-06-10T22:15:09Z",
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed_at": "2024-06-10T21:36:32Z",
"github_reviewed": true
}