Lucene search

K
osvGoogleOSV:GHSA-69P6-WVMQ-27GG
HistoryApr 20, 2022 - 12:00 a.m.

Command injection in ruby-git

2022-04-2000:00:33
Google
osv.dev
10

0.002 Low

EPSS

Percentile

55.7%

The package prior to v1.11.0 is vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way such that additional flags can be set. The additional flags can be used to perform a command injection.

Rows per page:
1-10 of 301