VDB
Sign up
HIGH8.1

GHSA-3xpw-vhmv-cw7h

Command injection in czproject/git-php

Quick fix

GHSA-3xpw-vhmv-cw7h — czproject/git-php: upgrade to the fixed version with the command below.

composer require czproject/git-php:^4.0.3

Details

The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/czproject/git-php
Introduced in: 0Fixed in: 4.0.3
Fixcomposer require czproject/git-php:^4.0.3

References