Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-21235
HistoryApr 01, 2022 - 4:15 p.m.

Command injection

2022-04-0116:15:00
PRIOn knowledge base
www.prio-n.com
4

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.3%

The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CPENameOperatorVersion
vcslt1.1.13

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.3%