CRITICAL 9.8 RubyGems

Command injection in ruby-git

GHSA-69p6-wvmq-27gg · BIT-git-2022-25648 · CVE-2022-25648 · SNYK-RUBY-GIT-2421270

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The package prior to v1.11.0 is vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way such that additional flags can be set. The additional flags can be used to perform a command injection.

Ready to move

Start Securing

Free, no credit card | First findings in minutes