Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-52005

Опубликовано: 15 янв. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

РелизСтатусПримечание
devel

deferred

esm-infra-legacy/xenial

deferred

esm-infra/bionic

deferred

esm-infra/focal

deferred

esm-infra/xenial

ignored

end of ESM support, was deferred
focal

ignored

end of standard support, was deferred
jammy

deferred

noble

deferred

oracular

ignored

end of life, was deferred
plucky

ignored

end of life, was deferred

Показывать по

EPSS

Процентиль: 40%
0.00503
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 8.8
nvd
больше 1 года назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

msrc
11 месяцев назад

The sideband payload is passed unfiltered to the terminal in git

CVSS3: 8.8
debian
больше 1 года назад

Git is a source code management tool. When cloning from a server (or f ...

rocky
около 1 года назад

Moderate: git security update

EPSS

Процентиль: 40%
0.00503
Низкий

8.8 High

CVSS3