Логотип exploitDog
bind:"CVE-2023-22742"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-22742"

Количество 10

Количество 10

ubuntu логотип

CVE-2023-22742

больше 2 лет назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-22742

больше 2 лет назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-22742

больше 2 лет назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-22742

12 месяцев назад

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-22742

больше 2 лет назад

libgit2 is a cross-platform, linkable library implementation of Git. W ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1909-1

около 2 лет назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1788-1

около 2 лет назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1570-1

больше 2 лет назад

Security update for libgit2

EPSS: Низкий
fstec логотип

BDU:2023-00574

больше 2 лет назад

Уязвимость библиотеки libssh2 реализации методов Git на языке C Libgit2, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20240729-05

11 месяцев назад

Уязвимость libgit2

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 5.9
0%
Низкий
12 месяцев назад
debian логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. W ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1909-1

Security update for libgit2

0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1788-1

Security update for libgit2

0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1570-1

Security update for libgit2

0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-00574

Уязвимость библиотеки libssh2 реализации методов Git на языке C Libgit2, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20240729-05

Уязвимость libgit2

CVSS3: 5.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу