CVE-2022-21223 Information
Description
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg) the url (and/or revision tag branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://snyk.io/vuln/SNYK-RUBY-COCOAPODSDOWNLOADER-2414280 https://github.com/CocoaPods/cocoapods-downloader/pull/127 The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg) the url (and/or revision tag branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: