PT-2022-14934 · Unknown · Cocoapods-Downloader
Alessio Della Libera
·
Published
2022-04-01
·
Updated
2022-04-08
·
CVE-2022-21223
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cocoapods-downloader versions prior to 1.6.2
Description
The issue allows for Command Injection via hg argument injection. When the download function is called using hg, the url and/or revision, tag, branch are passed to the hg clone command in a way that allows additional flags to be set, which can be used to perform a command injection.
Recommendations
For versions prior to 1.6.2, update to version 1.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the hg argument in the download function to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cocoapods-Downloader