logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-25860

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-25860

Description:
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221).
Last updated date:
02/02/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/02/2023
Reference url to background

https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3177391

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy