Логотип exploitDog
bind:"CVE-2024-52005"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-52005"

Количество 12

Количество 12

ubuntu логотип

CVE-2024-52005

около 1 года назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2024-52005

около 1 года назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-52005

около 1 года назад

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2024-52005

5 месяцев назад

The sideband payload is passed unfiltered to the terminal in git

EPSS: Низкий
debian логотип

CVE-2024-52005

около 1 года назад

Git is a source code management tool. When cloning from a server (or f ...

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2025:8414

6 месяцев назад

Moderate: git security update

EPSS: Низкий
rocky логотип

RLSA-2025:7482

4 месяца назад

Moderate: git security update

EPSS: Низкий
rocky логотип

RLSA-2025:7409

4 месяца назад

Moderate: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8414

8 месяцев назад

ELSA-2025-8414: git security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7482

8 месяцев назад

ELSA-2025-7482: git security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7409

9 месяцев назад

ELSA-2025-7409: git security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-02194

около 1 года назад

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 8.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

CVSS3: 8.8
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-52005

The sideband payload is passed unfiltered to the terminal in git

0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-52005

Git is a source code management tool. When cloning from a server (or f ...

CVSS3: 8.8
0%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:8414

Moderate: git security update

0%
Низкий
6 месяцев назад
rocky логотип
RLSA-2025:7482

Moderate: git security update

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2025:7409

Moderate: git security update

0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2025-8414

ELSA-2025-8414: git security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-7482

ELSA-2025-7482: git security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-7409

ELSA-2025-7409: git security update (MODERATE)

9 месяцев назад
fstec логотип
BDU:2025-02194

Уязвимость распределенной системы управления версиями Git, связанная с неправильным экранированием выходных данных, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных или выполнить произвольный код

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу