{"id":"GHSA-g397-v4w5-4m79","summary":"Command injection in cocoapods-downloader","details":"The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.","aliases":["CVE-2022-21223","SNYK-RUBY-COCOAPODSDOWNLOADER-2414280"],"modified":"2026-07-08T06:50:01.938540582Z","published":"2022-04-02T00:00:13Z","database_specific":{"github_reviewed_at":"2022-04-04T21:57:37Z","nvd_published_at":"2022-04-01T18:15:00Z","cwe_ids":["CWE-74","CWE-88"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21223"},{"type":"WEB","url":"https://github.com/CocoaPods/cocoapods-downloader/pull/127"},{"type":"PACKAGE","url":"https://github.com/CocoaPods/cocoapods-downloader"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cocoapods-downloader/CVE-2022-21223.yml"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-RUBY-COCOAPODSDOWNLOADER-2414280"}],"affected":[{"package":{"name":"cocoapods-downloader","ecosystem":"RubyGems","purl":"pkg:gem/cocoapods-downloader"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.2"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.2.0","0.3.0","0.4.0","0.4.1","0.5.0","0.6.0","0.6.1","0.7.0","0.7.1","0.7.2","0.8.0","0.8.1","0.9.0","0.9.1","0.9.2","0.9.3","1.0.0","1.0.0.beta.1","1.0.0.beta.2","1.0.0.beta.3","1.0.0.rc.1","1.0.1","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","1.2.1","1.2.2","1.3.0","1.4.0","1.5.0","1.5.1","1.6.0","1.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-g397-v4w5-4m79/GHSA-g397-v4w5-4m79.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}