GHSA-9p95-fxvg-qgq2

Suggest an improvement
Source
https://github.com/advisories/GHSA-9p95-fxvg-qgq2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-9p95-fxvg-qgq2/GHSA-9p95-fxvg-qgq2.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9p95-fxvg-qgq2
Aliases
Published
2022-12-06T06:30:17Z
Modified
2023-11-01T04:58:24.057225Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol
Details

The package simple-git before 3.15.0 is vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of CVE-2022-24066.

Database specific
{
    "nvd_published_at": "2022-12-06T05:15:00Z",
    "cwe_ids": [
        "CWE-78"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-12-07T14:15:26Z"
}
References

Affected packages

npm / simple-git

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.15.0