kellyselden/git-diff-apply

kellyselden/git-diff-apply

Releases137
Frequency3 weeks 19 hours
Last Release
Stars9
Use an unrelated remote repository to apply a git diff

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.