Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-40644

Опубликовано: 18 июл. 2024
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gix-path can be tricked into running another git.exe placed in an untrusted location by a limited user account on Windows systems. Windows permits limited user accounts without administrative privileges to create new directories in the root of the system drive. While gix-path first looks for git using a PATH search, in version 0.10.8 it also has a fallback strategy on Windows of checking two hard-coded paths intended to be the 64-bit and 32-bit Program Files directories. Existing functions, as well as the newly introduced exe_invocation function, were updated to make use of these alternative locations. This causes facilities in gix_path::env to directly execute git.exe in those locations, as well as to return its path or whatever configuration it reports to callers who rely on it. Although unusual setups where the system drive is not C:, or even where Program Files directories have non-default n

EPSS

Процентиль: 7%
0.00028
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.8
debian
больше 1 года назад

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of G ...

CVSS3: 6.8
github
больше 1 года назад

gix-path can use a fake program files location

EPSS

Процентиль: 7%
0.00028
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-345