CRITICAL 9.8 RubyGems
Git-fastclone passes user modifiable strings directly to a shell command
GHSA-mf6w-45cf-qhmp · CVE-2015-8969
Published · Modified
Description
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to cd and git clone commands in the library.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-8969
- WEB https://github.com/square/git-fastclone/pull/5
- WEB https://hackerone.com/reports/105190
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/git-fastclone/CVE-2015-8969.yml
- PACKAGE https://github.com/square/git-fastclone
- WEB https://web.archive.org/web/20161108132238/http://www.securityfocus.com/bid/81433
Ready to move
Start Securing
Free, no credit card | First findings in minutes