{"id":"CVE-2022-24440","aliases":["GHSA-7627-mp87-jf6q","SNYK-RUBY-COCOAPODSDOWNLOADER-2414278"],"url":"https://o3.security/vulnerability/CVE-2022-24440","summary":"Command Injection","details":"The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.","published":"2022-04-01T17:35:13.314Z","modified":"2026-08-12T03:51:16.534500697Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"cocoapods-downloader","fixedVersion":"1.6.0"},{"ecosystem":"RubyGems","name":"cocoapods-downloader","fixedVersion":"1.6.3"}],"fix":{"url":"https://github.com/CocoaPods/cocoapods-downloader/pull/124","label":"CocoaPods/cocoapods-downloader#124"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24440.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24440"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-RUBY-COCOAPODSDOWNLOADER-2414278"},{"type":"FIX","url":"https://github.com/CocoaPods/cocoapods-downloader/pull/124"},{"type":"FIX","url":"https://github.com/CocoaPods/cocoapods-downloader/pull/128"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.534500697Z"}}