PT-2022-10315 · Gitsome · Gitsome

Published

2022-06-01

·

Updated

2022-06-09

·

CVE-2021-34081

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gitsome versions prior to 0.3.0, specifically versions through 0.2.3
Description The issue allows attackers to execute arbitrary commands via a crafted tag name of the target git repository. This is an OS Command Injection vulnerability.
Recommendations For versions through 0.2.3, update to version 0.3.0 or later to resolve the issue.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34081
GHSA-9V73-X562-WV5X

Affected Products

Gitsome