PT-2022-16446 · Unknown+1 · Cookiecutter+1

Alessio Della Libera

·

Published

2022-06-03

·

Updated

2023-08-08

·

CVE-2022-24065

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cookiecutter versions prior to 2.1.1
Description The issue concerns Command Injection via hg argument injection. When the cookiecutter function is called from Python code with the checkout parameter, it is passed to the hg checkout command in a way that allows additional flags to be set. These additional flags can be used to perform a command injection.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the checkout parameter when calling the cookiecutter function from Python code to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-24065
GHSA-F4Q6-9QM4-H8J4
MGASA-2022-0258
PYSEC-2022-204
SNYK-PYTHON-COOKIECUTTER-2414281

Affected Products

Debian
Cookiecutter