Описание
gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| azl3 rust 1.75.0-31 on Azure Linux 3.0 | ||
| azl3 rust 1.96.1-1 on Azure Linux 3.0 |
Показывать по
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
(gitoxide gix-transport before 0.59.2 fails to filter control character ...)
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
gitoxide gix-transport before 0.59.2 fails to filter control character ...
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
EPSS
5.4 Medium
CVSS3