Skip to main content
CRITICAL

CVE-2022-24066

CVSS v3

9.8

CRITICAL

EPSS Score

3.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.

Technical details

Published
2022-04-01

Frequently asked questions

What is CVE-2022-24066?

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.

Is CVE-2022-24066 actively exploited?

Active exploitation of CVE-2022-24066 has not been confirmed. The EPSS score is 3.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-24066?

CVE-2022-24066 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-24066 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key