CVE-2022-21187

The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command execution.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:libvcs_project:libvcs:*:*:*:*:*:*:*:*

Information

Published : 2022-03-14 11:15

Updated : 2022-03-22 08:00


NVD link : CVE-2022-21187

Mitre link : CVE-2022-21187


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

libvcs_project

  • libvcs