CVE-2022-25866
25.04.2022, 17:15
The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.
Vendor | Product | Version |
---|---|---|
git-php_project | git-php | 𝑥 < 4.0.3 |
𝑥
= Vulnerable software versions
References