CRITICAL
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl
Published Jan 7, 2020
9.8
CRITICALCVSS 3.1
EPSS 2.15%
Description
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.
Affected products
- Vendor n/a Product Git-Diff-Apply Defaultn/a
- Version All versions prior to version 0.22.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Git-Diff-Apply | n/a |
|
- < 0.22.2
No data.
No Red Hat product state for this CVE.
git-diff-apply
npm
Introduced 0 Fixed 0.22.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | git-diff-apply | 0 | 0.22.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-84cm-v6jp-gjmr Advisory
- https://github.com/kellyselden/git-diff-apply/commit/106d61d3ae723b4257c2a13e67b95eb40a27e0b5 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10776
- https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774 ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774%2C x_refsource_CONFIRM
- https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774,
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-84cm-v6jp-gjmr | Advisory | |
| https://github.com/kellyselden/git-diff-apply/commit/106d61d3ae723b4257c2a13e67b95eb40a27e0b5 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10776 | ||
| https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774 | ExploitPatchThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774%2C | x_refsource_CONFIRM | |
| https://snyk.io/vuln/SNYK-JS-GITDIFFAPPLY-540774, |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jan 7, 2020
Updated Aug 4, 2024
Reserved Apr 3, 2019
Link CVE-2019-10776
CISA Vulnrichment
GHSA-84CM-V6JP-GJMR Updated n/a