CVE-2022-21187

The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command execution.
Configurations

Configuration 1

cpe:2.3:a:libvcs_project:libvcs:*:*:*:*:*:*:*:*

Information

Published : 2022-03-14 06:15

Updated : 2022-03-22 03:00


NVD link : CVE-2022-21187

Mitre link : CVE-2022-21187

Products Affected
No products.
CWE