VDB
Sign up
HIGH8.1

GHSA-7627-mp87-jf6q

Command injection in cocoapods-downloader

Quick fix

GHSA-7627-mp87-jf6q — cocoapods-downloader: upgrade to the fixed version with the command below.

bundle update cocoapods-downloader

Details

The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/cocoapods-downloader
Introduced in: 0Fixed in: 1.6.0
Fixbundle update cocoapods-downloader
RubyGems/cocoapods-downloader
Introduced in: 1.6.2Fixed in: 1.6.3
Fixbundle update cocoapods-downloader

References