CVE-2022-24512: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
.NET and Visual Studio Remote Code Execution Vulnerability.
References
- github.com/advisories/GHSA-c6w8-7mp3-34j9
- github.com/dotnet/announcements/issues/213
- github.com/dotnet/runtime/security/advisories/GHSA-c6w8-7mp3-34j9
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4TOGTZ2ZWDH662ZNFFSZVL3M5AJXV6JF/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIJGCVKLHVNLFBTEYJGWS43QG5DYJFBL/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MQLM7ABVCYJLF6JRPF3M3EBXW63GNC27/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRGSPXMZY4RM2L35FYHCXBFROLC23B2V/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OS2Q4NPRSARP7GHLKFLIYHFOPSYDO6MK/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXEQ3GQVELA2T4HNZG7VPMS2HDVXMJRG/
- nvd.nist.gov/vuln/detail/CVE-2022-24512
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-24512
Detect and mitigate CVE-2022-24512 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →