VYPR
High severity8.1NVD Advisory· Published Apr 1, 2022· Updated Jun 17, 2026

CVE-2022-24440

CVE-2022-24440

Description

The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cocoapods-downloaderRubyGems
< 1.6.01.6.0
cocoapods-downloaderRubyGems
>= 1.6.2, < 1.6.31.6.3

Affected products

4
  • cpe:2.3:a:cocoapods:cocoapods-downloader:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cocoapods:cocoapods-downloader:*:*:*:*:*:*:*:*range: <1.6.0
    • cpe:2.3:a:cocoapods:cocoapods-downloader:1.6.2:*:*:*:*:*:*:*
  • cocoapods-downloader/cocoapods-downloaderdescription
  • ghsa-coords
    Range: < 1.6.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.