Description

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.

INFO

Published Date :

2024-10-08T05:00:03.891Z

Last Modified :

2026-03-21T22:20:29.713Z

Source :

snyk
AFFECTED PRODUCTS

The following products are affected by CVE-2024-21532 vulnerability.

Vendors Products
Bahmutov
  • Ggit

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact