PT-2022-9420 · Git · Git

Paul-Emmanuel Raoul

·

Published

2022-03-17

·

Updated

2022-03-24

·

CVE-2021-23632

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions git versions prior to a fixed version
Description The issue is related to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, allowing execution of OS commands rather than just git commands. This can be exploited by providing malicious input to the repo.git function, which can lead to the execution of arbitrary OS commands. The estimated number of potentially affected devices is not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23632
GHSA-9GQR-XP86-F87H
SNYK-JS-GIT-1568518

Affected Products

Git