Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-41390

Опубликовано: 20 окт. 2025
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

A flaw was found in the git functionality of TruffleHog. Scanning a specially crafted git repository copied file-for-file, such as via tar, cp, rsync or other tools, with a malicious core.fsmonitor configuration option specified in the .git/config file can cause arbitrary code execution.

Отчет

This flaw affects only repositories copied file-for-file, such as via tar, cp, rsync or similar tools, it does not affect the regular use case of cloned repositories, limiting the impact of this vulnerability.

Меры по смягчению последствий

Before scanning the repository, check the contents of the .git/config file, looking for a malicious fsmonitor configuration option, such as system programs not related to project maintenance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-operator-bundleNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-operator-bundleNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/loki-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2405112TruffleHog: specially crafted git repository can lead to arbitrary code execution

EPSS

Процентиль: 0%
0.00005
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
6 месяцев назад

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

CVSS3: 7.8
github
6 месяцев назад

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

EPSS

Процентиль: 0%
0.00005
Низкий

7.8 High

CVSS3