9.8
CVSSv3

CVE-2022-24065

Published: 08/06/2022 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The package cookiecutter prior to 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cookiecutter project cookiecutter

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1013279 cookiecutter: CVE-2022-24065 Package: src:cookiecutter; Maintainer for src:cookiecutter is Vincent Bernat <bernat@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 20 Jun 2022 15:03:01 UTC Severity: important Tags: security Reply or subscribe to this bug ...