Количество 5
Количество 5
CVE-2024-32884
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by an application whose current working directory contains a malicious file, arbitrary code execution occurs. This is related to the patched vulnerability GHSA-rrjw-j4m2-mf34, but appears less severe due to a greater attack complexity. This issue has been patched in versions 0.35.0, 0.42.0 and 0.62.0.
CVE-2024-32884
gix-transport indirect code execution via malicious username
CVE-2024-32884
gitoxide is a pure Rust implementation of Git. `gix-transport` does no ...
GHSA-98p4-xjmm-8mfh
gix-transport indirect code execution via malicious username
BDU:2024-05715
Уязвимость библиотеки на языке Rust для работы с Git-репозиториями gitoxide, связанная с неверной нейтрализацией особых элементов в выходных данных, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-32884 gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by an application whose current working directory contains a malicious file, arbitrary code execution occurs. This is related to the patched vulnerability GHSA-rrjw-j4m2-mf34, but appears less severe due to a greater attack complexity. This issue has been patched in versions 0.35.0, 0.42.0 and 0.62.0. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
CVE-2024-32884 gix-transport indirect code execution via malicious username | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
CVE-2024-32884 gitoxide is a pure Rust implementation of Git. `gix-transport` does no ... | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-98p4-xjmm-8mfh gix-transport indirect code execution via malicious username | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
BDU:2024-05715 Уязвимость библиотеки на языке Rust для работы с Git-репозиториями gitoxide, связанная с неверной нейтрализацией особых элементов в выходных данных, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.4 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу