Описание
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchVendor Advisory
- Exploit
- Third Party AdvisoryVDB Entry
- Issue TrackingPatchVendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 1.9.4 (включая)
cpe:2.3:a:git_for_windows_project:git_for_windows:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00059
Низкий
7.8 High
CVSS3
4.4 Medium
CVSS2
Дефекты
CWE-426
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
EPSS
Процентиль: 18%
0.00059
Низкий
7.8 High
CVSS3
4.4 Medium
CVSS2
Дефекты
CWE-426