9.8
CVSSv3

CVE-2022-21235

Published: 01/04/2022 Updated: 08/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The package github.com/masterminds/vcs prior to 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vcs project vcs

Vendor Advisories

Synopsis Moderate: Release of containers for Red Hat OpenStack Platform 171 director Operator Type/Severity Security Advisory: Moderate Topic Red Hat OpenStack Platform 171 (Wallaby) director Operator containers are now available Description Release of Red Hat OpenStack Platform 171 (Wallaby) director Operator containers provides these ...
Synopsis Moderate: Release of containers for OSP 162z (Train) director Operator Type/Severity Security Advisory: Moderate Topic Red Hat OpenStack Platform (RHOSP) 162z (Train) director Operator containers are now available Description Release of Red Hat OpenStack Platform (RHOSP) 162z (Train) provides these changes: Solution Before ...
Synopsis Important: OpenShift Container Platform 41145 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41145 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...