{"id":"CVE-2022-24376","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-24376","summary":"OS Command Injection in git-promise","details":"All versions of package git-promise is vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue. \n### Credits\n @lirantal for discovering this vulnerability.","published":"2022-06-11T00:00:18Z","modified":"2023-11-08T04:08:30.988392Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"git-promise","fixedVersion":null}],"fix":{"url":"https://github.com/lirantal/git-promise/commit/030e4f993f3b65419d60f7f60e81e0a742b72e77","label":"lirantal/git-promise@030e4f9"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24376"},{"type":"WEB","url":"https://github.com/lirantal/git-promise/commit/030e4f993f3b65419d60f7f60e81e0a742b72e77"},{"type":"WEB","url":"https://gist.github.com/lirantal/9da1fceb32f5279eb76a5fc1cb9707dd"},{"type":"PACKAGE","url":"https://github.com/piuccio/git-promise"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-GITPROMISE-2434310"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:08:30.988392Z"}}