CRITICAL9.8
GHSA-mf6w-45cf-qhmp
Git-fastclone passes user modifiable strings directly to a shell command
Quick fix
GHSA-mf6w-45cf-qhmp — git-fastclone: upgrade to the fixed version with the command below.
bundle update git-fastcloneDetails
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to `cd ` and `git clone ` commands in the library.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8969[ADVISORY]
- https://github.com/square/git-fastclone/pull/5[WEB]
- https://hackerone.com/reports/105190[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/git-fastclone/CVE-2015-8969.yml[WEB]
- https://github.com/square/git-fastclone[PACKAGE]
- https://web.archive.org/web/20161108132238/http://www.securityfocus.com/bid/81433[WEB]