Логотип exploitDog
bind:"CVE-2024-52005"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-52005"

Количество 11

Количество 11

ubuntu логотип

CVE-2024-52005

10 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

EPSS: Низкий
redhat логотип

CVE-2024-52005

10 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-52005

10 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

EPSS: Низкий
msrc логотип

CVE-2024-52005

2 месяца назад

The sideband payload is passed unfiltered to the terminal in git

EPSS: Низкий
debian логотип

CVE-2024-52005

10 месяцев назад

Git is a source code management tool. When cloning from a server (or f ...

EPSS: Низкий
rocky логотип

RLSA-2025:8414

3 месяца назад

Moderate: git security update

EPSS: Низкий
rocky логотип

RLSA-2025:7482

около 1 месяца назад

Moderate: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8414

5 месяцев назад

ELSA-2025-8414: git security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7482

4 месяца назад

ELSA-2025-7482: git security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7409

6 месяцев назад

ELSA-2025-7409: git security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-02194

10 месяцев назад

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

0%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

0%
Низкий
10 месяцев назад
msrc логотип
CVE-2024-52005

The sideband payload is passed unfiltered to the terminal in git

0%
Низкий
2 месяца назад
debian логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or f ...

0%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:8414

Moderate: git security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:7482

Moderate: git security update

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2025-8414

ELSA-2025-8414: git security update (MODERATE)

5 месяцев назад
oracle-oval логотип
ELSA-2025-7482

ELSA-2025-7482: git security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2025-7409

ELSA-2025-7409: git security update (MODERATE)

6 месяцев назад
fstec логотип
BDU:2025-02194

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу