PT-2022-16447 · Unknown · Simple-Git

Liran Tal

·

Published

2022-04-01

·

Updated

2025-04-22

·

CVE-2022-24066

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions simple-git versions prior to 3.5.0
Description The issue arises from an incomplete fix of a previous command injection vulnerability, which only addressed the git fetch attack vector. The --upload-pack feature of git, also supported for git clone, was not covered by the prior fix, leaving it vulnerable to command injection.
Recommendations For versions prior to 3.5.0, update to simple-git@3.5.0 to resolve the issue. As a temporary workaround, consider restricting the use of the --upload-pack feature in git clone operations until the update is applied.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2022-24066
GHSA-28XR-MWXG-3QC8
SNYK-JAVA-ORGWEBJARSNPM-2434820
SNYK-JS-SIMPLEGIT-2434306

Affected Products

Simple-Git