Description
All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be fetched and then concatenates this string along with a git command which is then passed to the unsafe exec() Node.js child process API.
INFO
Published Date :
2024-10-08T05:00:03.891Z
Last Modified :
2026-03-21T22:20:29.713Z
Source :
snyk
AFFECTED PRODUCTS
The following products are affected by CVE-2024-21532 vulnerability.
| Vendors | Products |
|---|---|
| Bahmutov |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-21532.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact