Логотип exploitDog
bind:"BDU:2025-02194" OR bind:"CVE-2024-52005"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-02194" OR bind:"CVE-2024-52005"

Количество 7

Количество 7

fstec логотип

BDU:2025-02194

5 месяцев назад

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-52005

5 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

EPSS: Низкий
redhat логотип

CVE-2024-52005

5 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-52005

5 месяцев назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

EPSS: Низкий
debian логотип

CVE-2024-52005

5 месяцев назад

Git is a source code management tool. When cloning from a server (or f ...

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8414

17 дней назад

ELSA-2025-8414: git security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7409

30 дней назад

ELSA-2025-7409: git security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-02194

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

0%
Низкий
5 месяцев назад
redhat логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or f ...

0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-8414

ELSA-2025-8414: git security update (MODERATE)

17 дней назад
oracle-oval логотип
ELSA-2025-7409

ELSA-2025-7409: git security update (MODERATE)

30 дней назад

Уязвимостей на страницу