Описание
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
A flaw was found in gix-transport. This vulnerability allows a remote attacker to inject control characters, specifically NUL, Carriage Return (CR), and Line Feed (LF) bytes, into git-daemon connect requests by crafting malicious git URLs. This injection can lead to spoofing of virtual hosts or the insertion of newlines into daemon requests and logs, potentially causing information disclosure or unexpected behavior.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | igvm | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rust | Fix deferred | ||
| Red Hat Enterprise Linux 8 | rust-toolset:rhel8/rust | Fix deferred | ||
| Red Hat Enterprise Linux 9 | rust | Fix deferred | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rust | Fix deferred | ||
| Red Hat Hardened Images | openshell | Not affected | ||
| Red Hat Hardened Images | rust | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
(gitoxide gix-transport before 0.59.2 fails to filter control character ...)
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
gitoxide gix-transport before 0.59.2 fails to filter control character ...
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
EPSS
5.4 Medium
CVSS3