GHSA-28xr-mwxg-3qc8

    Dashboard / Vulnerabilities / GHSA-28xr-mwxg-3qc8

    GHSA-28xr-mwxg-3qc8

    Published: 2 Apr 2022Last Modified: 14 Jan 2025

    Summary: Command injection in simple-git

    Details: `simple-git` (maintained as [git-js](https://github.com/steveukx/git-js) named repository on GitHub) is a light weight interface for running git commands in any node.js application.The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover. A fix was released in [email protected].

    Affected packages

    Package

    Name: simple-git

    Purl: pkg:npm/simple-git

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.5.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-28xr-mwxg-3qc8 | CVE-DB