

Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
December 12, 2022
Rewterz Threat Advisory – CVE-2022-41735 – IBM Business Process Manager Vulnerability
December 12, 2022
Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
December 12, 2022
Rewterz Threat Advisory – CVE-2022-41735 – IBM Business Process Manager Vulnerability
December 12, 2022Severity
High
Analysis Summary
CVE-2022-25912
Node.js simple-git module could allow a remote attacker to execute arbitrary code on the system, caused by a flaw when enabling the ext transport protocol. By sending a specially-crafted request using the clone() method, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
Code Execution
Indicators Of Compromise
CVE
- CVE-2022-25912
Affected Vendors
Node.js
Affected Products
- Node.js simple-git 3.14.1
Remediation
Upgrade to the latest version of simple-git, available from the git-js GIT Repository.