CVE-2022-36069 affects Poetry, a Python dependency manager, allowing for potential code execution. It arises when Poetry processes Git repository URLs containing user-supplied input that begins with a dash, causing it to be interpreted as an optional argument rather than a positional one. This vulnerability has a CVSS score of 7.3 (HIGH) due to its high impact on confidentiality, integrity, and availability, though it requires user interaction and local access. While not actively exploited or having public exploit code, it poses a risk to developers handling untrusted files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.9CPE matchmatch criteria | cpe:2.3:a:python-poetry:poetry:*:*:*:*:*:python:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:python-poetry:poetry:1.2.0:alpha1:*:*:*:python:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:python-poetry:poetry:1.2.0:alpha2:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.