PT-2022-9420 · Git · Git
Paul-Emmanuel Raoul
·
Published
2022-03-17
·
Updated
2022-03-24
·
CVE-2021-23632
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
git versions prior to a fixed version
Description
The issue is related to Remote Code Execution (RCE) due to missing sanitization in the
Git.git method, allowing execution of OS commands rather than just git commands. This can be exploited by providing malicious input to the repo.git function, which can lead to the execution of arbitrary OS commands. The estimated number of potentially affected devices is not specified.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Git