GHSA-mf6w-45cf-qhmp
Dashboard / Vulnerabilities / GHSA-mf6w-45cf-qhmp
Summary: Git-fastclone passes user modifiable strings directly to a shell command
Details: git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to `cd ` and `git clone ` commands in the library.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-8969, https://github.com/square/git-fastclone/pull/5, https://hackerone.com/reports/105190, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/git-fastclone/CVE-2015-8969.yml, https://github.com/square/git-fastclone, https://web.archive.org/web/20161108132238/http://www.securityfocus.com/bid/81433
Affected packages
Package
Name: git-fastclone
Purl: pkg:gem/git-fastclone
Affected ranges
Type: ECOSYSTEM
Events:
