Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c5j-jmhx-q2gr

Опубликовано: 28 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.1

Описание

Duplicate Advisory: gix-transport code execution vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-rrjw-j4m2-mf34. This link is maintained to preserve external references.

Original Description

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

Пакеты

Наименование

gix-transport

rust
Затронутые версииВерсия исправления

< 0.36.1

0.36.1

4.1 Medium

CVSS3

Дефекты

CWE-78

4.1 Medium

CVSS3

Дефекты

CWE-78