{"id":"GHSA-qffw-8wg7-h665","summary":"Command injection in git-interface","details":"A command injection vulnerability exists in git-interface in the GitHub repository yarkeev/git-interface prior to 2.1.2. If both the git remote and destination directory are provided by user input, then the use of an `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.","aliases":["CVE-2022-1440"],"modified":"2023-11-08T04:07:49.055507Z","published":"2022-04-23T00:03:01Z","database_specific":{"nvd_published_at":"2022-04-22T18:15:00Z","cwe_ids":["CWE-78","CWE-88"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-04-26T13:06:52Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1440"},{"type":"WEB","url":"https://github.com/yarkeev/git-interface/commit/f828aa790016fee3aa667f7b44cf94bf0aa8c60d"},{"type":"PACKAGE","url":"https://github.com/yarkeev/git-interface"},{"type":"WEB","url":"https://huntr.dev/bounties/cdc25408-d3c1-4a9d-bb45-33b12a715ca1"}],"affected":[{"package":{"name":"git-interface","ecosystem":"npm","purl":"pkg:npm/git-interface"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-qffw-8wg7-h665/GHSA-qffw-8wg7-h665.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}