PT-2020-21313 · Github · Git-Tags-Remote

Published

2020-07-29

·

Updated

2020-07-29

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions git-tags-remote versions (affected versions not specified)
Description The issue concerns a command injection problem. It arises because the package does not properly sanitize the repository input, which is then directly passed to an exec call on the get function. This could potentially allow attackers to execute arbitrary code on the system if the repo value passed to the function is under user control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-GM9X-Q798-HMR4

Affected Products

Git-Tags-Remote