VDB
CVE-2022-40764
CVE-2022-40764
PUBLISHED
CVSS 7.800000190734863 HIGH
Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.
EPSS 0.57% · 46.0th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.57%
46.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | snyk-go-plugin | 0 |
| n/a | n/a | n/a |
| snyk | golang_cli | 0 |
| snyk | cli | 0 |
| npm | snyk | 0 |
Timeline
- Oct 3, 2022 CVE Published
- Oct 4, 2022 EPSS Score
- Oct 6, 2022 CVE Updated
- Nov 18, 2022 EPSS Score
- Feb 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
- Jun 29, 2023 EPSS Score
- Aug 13, 2023 EPSS Score
- Sep 27, 2023 EPSS Score
- Nov 10, 2023 EPSS Score
- Feb 8, 2024 EPSS Score
References
- https://github.com/snyk/snyk-go-plugin/releases/tag/v1.19.1 url
- https://github.com/snyk/cli/releases/tag/v1.996.0 url
- https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution/ url
- https://support.snyk.io/hc/en-us/articles/7015908293789-CVE-2022-40764-Command-Injection-vulnerability-affecting-Snyk-CLI-versions-prior-to-1-996-0 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-40764 advisory
- https://github.com/snyk/cli package
- https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution url