Логотип exploitDog
bind:"CVE-2023-22742"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-22742"

Количество 10

Количество 10

ubuntu логотип

CVE-2023-22742

почти 3 года назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-22742

почти 3 года назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-22742

почти 3 года назад

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-22742

больше 1 года назад

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-22742

почти 3 года назад

libgit2 is a cross-platform, linkable library implementation of Git. W ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1909-1

больше 2 лет назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1788-1

почти 3 года назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1570-1

почти 3 года назад

Security update for libgit2

EPSS: Низкий
fstec логотип

BDU:2023-00574

почти 3 года назад

Уязвимость библиотеки libssh2 реализации методов Git на языке C Libgit2, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20240729-05

больше 1 года назад

Уязвимость libgit2

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 5.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. W ...

CVSS3: 5.3
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1909-1

Security update for libgit2

0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1788-1

Security update for libgit2

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1570-1

Security update for libgit2

0%
Низкий
почти 3 года назад
fstec логотип
BDU:2023-00574

Уязвимость библиотеки libssh2 реализации методов Git на языке C Libgit2, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 5.3
0%
Низкий
почти 3 года назад
redos логотип
ROS-20240729-05

Уязвимость libgit2

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу