CRITICAL

CVE-2022-24437

CVSS v3

9.8

CRITICAL

EPSS Score

10.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

Technical details

Published
5/1/2022

Frequently asked questions

What is CVE-2022-24437?

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

Is CVE-2022-24437 actively exploited?

Active exploitation of CVE-2022-24437 has not been confirmed. The EPSS score is 10.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-24437?

CVE-2022-24437 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-24437 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.