Git Shallow Clone Vulnerable to Command Injection
CVE-2024-21531

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2024

Summary

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone function.

Affected Version(s)

git-shallow-clone 0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Liran Tal - Snyk Research Team
.