#VU69505 OS Command Injection in Sourcegraph - CVE-2022-41943
Published: November 22, 2022
Sourcegraph
Sourcegraph
Description
The vulnerability allows a remote privileged user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the experimental customGitFetch feature . A remote privileged user (site admin) can pass specially crafted data to the application and execute arbitrary OS commands on the Gitserver.