Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-24065
Description:The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
Test IDs: 1.3.6.1.4.1.25623.1.0.820772   1.3.6.1.4.1.25623.1.1.10.2022.0258   1.3.6.1.4.1.25623.1.0.820760  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-24065
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G5TXC4JYTNGOUFMCXPZ6QKWEZN3URTAK/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQKWT7SGFDCUPPLDIELTN7FVTHWDL5YK/
https://github.com/cookiecutter/cookiecutter/commit/fdffddb31fd2b46344dfa317531ff155e7999f77
https://github.com/cookiecutter/cookiecutter/commit/fdffddb31fd2b46344dfa317531ff155e7999f77
https://github.com/cookiecutter/cookiecutter/releases/tag/2.1.1
https://github.com/cookiecutter/cookiecutter/releases/tag/2.1.1
https://snyk.io/vuln/SNYK-PYTHON-COOKIECUTTER-2414281
https://snyk.io/vuln/SNYK-PYTHON-COOKIECUTTER-2414281




© 1998-2025 E-Soft Inc. All rights reserved.