Lucene search

K
osvGoogleOSV:GHSA-5875-M6JQ-VF78
HistoryMay 14, 2022 - 12:01 a.m.

Command injection in workspace-tools

2022-05-1400:01:08
Google
osv.dev
14

0.002 Low

EPSS

Percentile

53.0%

The package workspace-tools before 0.18.4 is vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CPENameOperatorVersion
workspace-toolslt0.18.4

0.002 Low

EPSS

Percentile

53.0%

Related for OSV:GHSA-5875-M6JQ-VF78