#VU69504 OS Command Injection in Sourcegraph - CVE-2022-41942
Published: November 22, 2022
Sourcegraph
Sourcegraph
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation on the host parameter of the /list-gitolite endpoint. A remote user can pass specially crafted data to gitserver and execute arbitrary OS commands inside the container.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.