VulnerabilityModified
CVE-2022-25766
The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection.
HIGH 8.8EPSS 34.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible to get arbitrary command execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 34.30% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- ungit project/ungit
- Source
- report@snyk.io
References
- https://github.com/FredrikNoren/ungit/blob/master/CHANGELOG.md%231520Broken Link, Release Notes, Third Party Advisory
- https://github.com/FredrikNoren/ungit/pull/1510Exploit, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-UNGIT-2414099Release Notes, Third Party Advisory
- https://github.com/FredrikNoren/ungit/blob/master/CHANGELOG.md%231520Broken Link, Release Notes, Third Party Advisory
- https://github.com/FredrikNoren/ungit/pull/1510Exploit, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-UNGIT-2414099Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.