Remote Code Execution (RCE)
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 2.9%
exploitation probability
2.9%top 14% of all CVEs
observed exploitation
nono source reports it
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P
Affected products
n/a · simple-gitReferences
https://github.com/steveukx/git-js/blob/main/docs/PLUGIN-UNSAFE-ACTIONS.md%23overriding-allowed-protocolshttps://github.com/steveukx/git-js/commit/774648049eb3e628379e292ea172dccaba610504https://github.com/steveukx/git-js/releases/tag/simple-git%403.15.0https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3153532https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221