Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39165
HistoryFeb 08, 2023 - 9:25 a.m.

Remote Code Execution (RCE)

2023-02-0809:25:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
remote code execution
simple-git
vulnerability
improper sanitization
clone
pull
push
listremote
arbitrary code

0.021 Low

EPSS

Percentile

89.2%

simple-git is vulnerable to Remote Code Execution (RCE). The vulnerability exists due to improper sanitization of the clone(), pull(), push() and listRemote() methods which allows an attacker to execute arbitrary code.

CPENameOperatorVersion
simple-gitle3.15.1
simple-gitle3.15.1

0.021 Low

EPSS

Percentile

89.2%