VDB
Sign up
HIGH8.0

GHSA-pphf-gfrm-v32r

Code injection in ruby git

Quick fix

GHSA-pphf-gfrm-v32r — git: upgrade to the fixed version with the command below.

bundle update git

Details

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/git
Introduced in: 0Fixed in: 1.13.0
Fixbundle update git

References