Lucene search

K
cvelistSnykCVELIST:CVE-2022-24065
HistoryJun 03, 2022 - 8:00 p.m.

CVE-2022-24065 Command Injection

2022-06-0320:00:14
snyk
www.cve.org
4
cookiecutter
command injection
python code

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P

AI Score

10

Confidence

High

EPSS

0.01

Percentile

84.1%

The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CNA Affected

[
  {
    "product": "cookiecutter",
    "vendor": "n/a",
    "versions": [
      {
        "lessThan": "2.1.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P

AI Score

10

Confidence

High

EPSS

0.01

Percentile

84.1%