simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol
High severity
GitHub Reviewed
Published
Dec 6, 2022
to the GitHub Advisory Database
•
Updated Aug 17, 2023
Description
Published by the National Vulnerability Database
Dec 6, 2022
Published to the GitHub Advisory Database
Dec 6, 2022
Reviewed
Dec 7, 2022
Last updated
Aug 17, 2023
The package simple-git before 3.15.0 is vulnerable to Remote Code Execution (RCE) when enabling the
ext
transport protocol, which makes it exploitable viaclone()
method. This vulnerability exists due to an incomplete fix of CVE-2022-24066.References