#VU24212 OS Command Injection in git-diff-apply - CVE-2019-10776
Published: January 13, 2020
git-diff-apply
Kelly Selden
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists in the "index.js" file due to the "run" command executes the git command with a user controlled variable called remoteUrl.. A remote unauthenticated attacker can execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.