cbcvebase.
CVE-2022-20001
published 2022-03-14

CVE-2022-20001: fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository…

PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.42%
70.1th percentile
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianfish< fish 3.4.0+ds-1 (bookworm)fish 3.4.0+ds-1 (bookworm)
debianpowerline-gitstatus< powerline-gitstatus 1.3.2-1 (bookworm)powerline-gitstatus 1.3.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fishshellfish>= 0 < 3.1.2-3+deb11u13.1.2-3+deb11u1
fishshellfish>= 0 < 3.4.0+ds-13.4.0+ds-1
fishshellfish>= 0 < 3.4.0+ds-13.4.0+ds-1
fishshellfish>= 0 < 3.4.0+ds-13.4.0+ds-1
fishshellfish3.1.0 – 3.3.1
msrccbl2_fish_on_cbl_mariner_2.0
powerline_gitstatus_projectpowerline_gitstatus< 1.3.21.3.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.8HIGH
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.