VDB
Sign up
CRITICAL9.8

GHSA-69p6-wvmq-27gg

Command injection in ruby-git

Quick fix

GHSA-69p6-wvmq-27gg — git: upgrade to the fixed version with the command below.

bundle update git

Details

The package prior to v1.11.0 is vulnerable to Command Injection via git argument injection. When calling the `fetch(remote = 'origin', opts = {})` function, the remote parameter is passed to the `git fetch` subcommand in a way such that additional flags can be set. The additional flags can be used to perform a command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/git
Introduced in: 0Fixed in: 1.11.0
Fixbundle update git

References