Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-6257

Опубликовано: 25 июн. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.4

Описание

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

focal

ignored

end of standard support, was needed
jammy

needed

mantic

ignored

end of life, was needs-triage
noble

needed

oracular

ignored

end of life, was needed

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

focal

ignored

end of standard support, was needed
jammy

needed

mantic

ignored

end of life, was needs-triage
noble

needed

oracular

ignored

end of life, was needed
plucky

DNE

Показывать по

EPSS

Процентиль: 70%
0.00724
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
redhat
больше 1 года назад

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

CVSS3: 8.4
nvd
больше 1 года назад

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

CVSS3: 8.4
msrc
больше 1 года назад

HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation

CVSS3: 8.4
debian
больше 1 года назад

HashiCorp\u2019s go-getter library can be coerced into executing Git u ...

CVSS3: 8.4
redos
около 1 года назад

Уязвимость terraform

EPSS

Процентиль: 70%
0.00724
Низкий

8.4 High

CVSS3