HIGH8.1
GHSA-8jmw-wjr8-2x66
Command injection in git-clone
Details
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the `--upload-pack` feature of git.
## Credits
Credit to @lirantal for discovering this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/git-clone
Introduced in:
0No fixed version published yet for git-clone (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25900[ADVISORY]
- https://github.com/jaz303/git-clone/commit/fd330459593aef7c7a8c54d786e3c4d5722749f9[WEB]
- https://gist.github.com/lirantal/9441f3a1212728476f7a6caa4acb2ccc[WEB]
- https://github.com/jaz303/git-clone[PACKAGE]
- https://snyk.io/vuln/SNYK-JS-GITCLONE-2434308[WEB]