diffy
Convenient diffing in ruby
Activity
- Latest release
- 1y ago
- Total releases
- 34
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Nov 22, 2010
| Version | Released | |
|---|---|---|
3.4.4
patch
| ||
3.4.3
patch
| ||
3.4.2
patch
| ||
3.4.1
patch
| ||
3.4.0
minor
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.7
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.6
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.5
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.4
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.3
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.2
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.1.4
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.1.3
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.9
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.10
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.8
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.7
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.6
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
1.1.0
initial
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2022-33127
GHSA-5ww9-9qp2-x524
Jun 24, 2022
Improper handling of double quotes in file name in Diffy in Windows environment
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string. Affected versions
1.1.0
2.0.0
2.0.1
2.0.10
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
+ 18 more Show less
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.2.0
3.2.1
3.3.0
3.4.0
Fixed in
3.4.1
References
Updated Dec 08, 2024 · Source: OSV.dev |