VYPR
High severity8.1NVD Advisory· Published Apr 19, 2022· Updated Jun 17, 2026

CVE-2022-25648

CVE-2022-25648

Description

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
gitRubyGems
< 1.11.01.11.0

Affected products

9
  • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
  • Git/Git2 versions
    cpe:2.3:a:git:git:*:*:*:*:*:ruby:*:*+ 1 more
    • cpe:2.3:a:git:git:*:*:*:*:*:ruby:*:*range: <1.11.0
    • (no CPE)
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
  • osv-coords2 versions
    < 1.11.0+ 1 more
    • (no CPE)range: < 1.11.0
    • (no CPE)range: < 1.11.0

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.