gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author and committer names, commit messages, or other metadata. Such text may be written as part of the output of a command, as well as appearing in error messages when an operation fails. This sometimes allows an untrusted repository to misrepresent its contents and to alter or concoct error messages.
History

Thu, 22 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Byron
Byron gitoxide
CPEs cpe:2.3:a:byron:gitoxide:*:*:*:*:*:*:*:*
Vendors & Products Byron
Byron gitoxide
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author and committer names, commit messages, or other metadata. Such text may be written as part of the output of a command, as well as appearing in error messages when an operation fails. This sometimes allows an untrusted repository to misrepresent its contents and to alter or concoct error messages.
Title gitoxide-core does not neutralize special characters for terminals
Weaknesses CWE-150
References
Metrics cvssV3_1

{'score': 2.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-22T14:19:31.070Z

Updated: 2024-08-22T21:45:40.662Z

Reserved: 2024-08-16T14:20:37.323Z

Link: CVE-2024-43785

cve-icon Vulnrichment

Updated: 2024-08-22T16:38:16.592Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-22T15:15:16.670

Modified: 2024-08-23T16:18:28.547

Link: CVE-2024-43785

cve-icon Redhat

No data.