cocoapods-downloader
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cocoapods-downloaderpage 1 of 1
- CVE-2022-21223HIGHCVSS 8.1EG 8.1✓ Fixed in 1.6.22022-04-01
vulnerable: 0.1.0 ... 1.6.1 (38 versions)
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a …
- CVE-2022-24440HIGHCVSS 8.1EG 8.1✓ Fixed in 1.6.32022-04-01
vulnerable: 1.6.2
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch …
Check whether cocoapods-downloader is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cocoapods-downloader CVEs against the assets you own.
Start Free Scan →