Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27614

Опубликовано: 08 июл. 2025
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

Отчет

The Red Hat Product Security team has rated this vulnerability as having a Moderate impact as it depends on the user to be tricked to run the command using the malicious file as parameter.

Меры по смягчению последствий

There's no known mitigation for this issue besides avoid using gitk with untrusted repositories or unstrusted files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitUnder investigation
Red Hat Enterprise Linux 7gitUnder investigation
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Enterprise Linux 10gitFixedRHSA-2025:1153322.07.2025
Red Hat Enterprise Linux 8gitFixedRHSA-2025:1153423.07.2025
Red Hat Enterprise Linux 9gitFixedRHSA-2025:1146221.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 4%
0.00022
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

CVSS3: 8.6
nvd
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

msrc
около 1 месяца назад

MITRE: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability

CVSS3: 8.6
debian
около 1 месяца назад

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Gi ...

CVSS3: 8.6
fstec
около 1 месяца назад

Уязвимость команды gitk filename браузера Gitk, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 4%
0.00022
Низкий

6.3 Medium

CVSS3