GHSA-pfpr-3463-c6jh

    Dashboard / Vulnerabilities / GHSA-pfpr-3463-c6jh

    GHSA-pfpr-3463-c6jh

    Published: 9 Jan 2023Last Modified: 4 Apr 2025

    Summary: ruby-git has potential remote code execution vulnerability

    Details: The git gem, between versions 1.2.0 and 1.12.0, incorrectly parsed the output of the `git ls-files` command using `eval()` to unescape quoted file names. If a file name was added to the git repository contained special characters, such as `\n`, then the `git ls-files` command would print the file name in quotes and escape any special characters. If the `Git#ls_files` method encountered a quoted file name it would use `eval()` to unquote and unescape any special characters, leading to potential remote code execution. Version 1.13.0 of the git gem was released which correctly parses any quoted file names.

    Affected packages

    Package

    Name: git

    Purl: pkg:gem/git

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.2.0
    Fixed -1.13.0

    Affected versions

    1.10.0
    1.10.1
    1.10.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-pfpr-3463-c6jh | CVE-DB