Skip to main content

CVE-2022-24066

8.1
HIGHCVSS v3.1 Base Score
3.02%
LOW RiskEPSS (87th percentile)

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which the prior fix didn't cover.

Published: 4/1/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

3.02%LOW Exploitation Risk
87th percentile

This vulnerability has a 3.02% probability of being exploited in the next 30 days, ranking higher than 87% of all scored CVEs.

Related Vulnerabilities