CVE-2022-24066: Command Injection
simple-git (maintained as git-js named repository on GitHub) is a light weight interface for running git commands in any node.js application.The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of CVE-2022-24433 which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover. A fix was released in simple-git@3.5.0.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-24066.
What is the severity of CVE-2022-24066?
The severity of CVE-2022-24066 is critical with a CVSS score of 9.8.
What is the affected software?
The affected software is simple-git before version 3.5.0.
What is the description of CVE-2022-24066?
CVE-2022-24066 is a command injection vulnerability in the simple-git package before version 3.5.0.
How do I fix CVE-2022-24066?
To fix CVE-2022-24066, upgrade to version 3.5.0 or later of the simple-git package.