REDHAT-BUG-2461750: High severity npm/simple-git vulnerability
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
simple-gitto a version that resolves this vulnerability.Fixed in 3.36.0 - Configuration
Ensure protocol.ext.allow is NOT set to "always" (untrusted users must not be able to enable it via simple-git options, and the equivalent --config form should not be controllable by untrusted input).
simple-git / git configuration protocol.ext.allow = always - Compensating control
Prevent untrusted input from reaching the options argument passed to simple-git (validate/allowlist inputs so attackers cannot supply protocol.ext.allow=always or an ext:: clone source).
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2461750?
The severity of REDHAT-BUG-2461750 is high, rated at 7.
What is the description of REDHAT-BUG-2461750?
REDHAT-BUG-2461750 relates to a Remote Code Execution vulnerability in versions of simple-git prior to 3.36.0.
How do I fix REDHAT-BUG-2461750?
To resolve REDHAT-BUG-2461750, upgrade the simple-git package to version 3.36.0 or later.
What versions are affected by REDHAT-BUG-2461750?
Versions of simple-git before 3.36.0 are vulnerable to REDHAT-BUG-2461750.
What type of vulnerability is REDHAT-BUG-2461750?
REDHAT-BUG-2461750 is categorized as a Remote Code Execution (RCE) vulnerability due to untrusted input.