CVE-2021-44685
Last modified
CVE-2021-44685 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).. EPSS estimates a 3.47% chance of exploitation in the next 30 days.
Description
Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Git-It Project | Git-It | <= 4.4.0 |
References
- https://github.com/dwisiswant0/advisory/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jlord/git-it-electron/releasesRelease Notes, Third Party Advisory
- https://github.com/dwisiswant0/advisory/issues/3Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jlord/git-it-electron/releasesRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-44685?
How severe is CVE-2021-44685?
How do I fix CVE-2021-44685?
Are you affected by CVE-2021-44685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
