

Rewterz Threat Advisory – Multiple IBM Vulnerabilities
April 4, 2022
Rewterz Threat Advisory – CVE-2022-25598 – Apache DolphinScheduler Vulnerability
April 4, 2022
Rewterz Threat Advisory – Multiple IBM Vulnerabilities
April 4, 2022
Rewterz Threat Advisory – CVE-2022-25598 – Apache DolphinScheduler Vulnerability
April 4, 2022Severity
High
Analysis Summary
CVE-2022-24066
Node.js simple-git module could allow a remote attacker to execute arbitrary commands on the system, caused by command injection flaw. By sending a specially-crafted request using the the –upload-pack feature, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
- Command Execution
Indicator Of Compromise
CVE
- CVE-2022-24066
Affected Vendors
Node.js
Affected Products
- Node.js simple-git 3.4.0
Remediation
Upgrade to the latest version of simple-git, available from the git-js GIT Repository.