Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
CRITICAL 9.8 RubyGems

Git-fastclone passes user modifiable strings directly to a shell command

GHSA-mf6w-45cf-qhmp · CVE-2015-8969

Published · Modified

Description

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to cd and git clone commands in the library.

Ready to move

Start Securing

Free, no credit card | First findings in minutes