Ggit Vulnerable to Command Injection via FetchTags(branch) API
CVE-2024-21532
7.3HIGH
Key Information
- Vendor
- Ggit
- Status
- Ggit
- Vendor
- CVE Published:
- 8 October 2024
Summary
All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.
Affected Version(s)
ggit < 0
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Liran Tal