GHSA-wjqc-j537-j9gj

Suggest an improvement
Source
https://github.com/advisories/GHSA-wjqc-j537-j9gj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-wjqc-j537-j9gj/GHSA-wjqc-j537-j9gj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wjqc-j537-j9gj
Aliases
Published
2021-12-08T00:01:44Z
Modified
2023-11-08T04:07:18Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Command injection in git-it-electron
Details

Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).

Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-12-09T17:57:55Z",
    "nvd_published_at":  "2021-12-07T00:15:00Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / git-it-electron

Package

Name
git-it-electron
View open source insights on deps.dev
Purl
pkg:npm/git-it-electron

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.3.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-wjqc-j537-j9gj/GHSA-wjqc-j537-j9gj.json"