Command injection in git-interface
Critical severity
GitHub Reviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Apr 22, 2022
Published to the GitHub Advisory Database
Apr 23, 2022
Reviewed
Apr 26, 2022
Last updated
Feb 1, 2023
A command injection vulnerability exists in git-interface in the GitHub repository yarkeev/git-interface prior to 2.1.2. If both the git remote and destination directory are provided by user input, then the use of an
--upload-pack
command-line argument feature of git is also supported forgit clone
, which would then allow for any operating system command to be spawned by the attacker.References