{"id":"GHSA-chj3-f7xw-367m","summary":"OS Command Injection in git-promise","details":"All versions of package git-promise is vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue. \n### Credits\n @lirantal for discovering this vulnerability.","aliases":["CVE-2022-24376"],"modified":"2023-11-08T04:08:30.988392Z","published":"2022-06-11T00:00:18Z","database_specific":{"cwe_ids":["CWE-77","CWE-88"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-17T00:56:05Z","nvd_published_at":"2022-06-10T20:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24376"},{"type":"WEB","url":"https://github.com/lirantal/git-promise/commit/030e4f993f3b65419d60f7f60e81e0a742b72e77"},{"type":"WEB","url":"https://gist.github.com/lirantal/9da1fceb32f5279eb76a5fc1cb9707dd"},{"type":"PACKAGE","url":"https://github.com/piuccio/git-promise"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-GITPROMISE-2434310"}],"affected":[{"package":{"name":"git-promise","ecosystem":"npm","purl":"pkg:npm/git-promise"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-chj3-f7xw-367m/GHSA-chj3-f7xw-367m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}