This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2022-25912 (Critical) detected in simple-git-1.113.0.tgz #248
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-25912 - Critical Severity Vulnerability
Simple GIT interface for node.js
Library home page: https://registry.npmjs.org/simple-git/-/simple-git-1.113.0.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/simple-git/package.json
Dependency Hierarchy:
Found in HEAD commit: 31f5cb63b4ed71bb0a592036c13801d050e24f93
Found in base branch: master
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of CVE-2022-24066.
Publish Date: 2022-12-06
URL: CVE-2022-25912
Base Score Metrics:
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2022-25912
Release Date: 2022-12-06
Fix Resolution (simple-git): 3.15.0
Direct dependency fix Resolution (lint-staged): 9.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: