CVE-2024-35186
CVSS V2 None
CVSS V3 None
Description
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality, integrity, and availability, but creating files outside a working tree without attempting to execute code can directly impact integrity as well. This vulnerability has been patched in version(s) 0.36.0.
Overview
- CVE ID
- CVE-2024-35186
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-05-23T08:55:20.653Z
- Last Modified Date
- 2024-06-04T17:34:36.271Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/Byron/gitoxide/security/advisories/GHSA-7w47-3wg8-547c | x_refsource_CONFIRM |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-35186 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35186 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 13:50:15 | Added to TrackCVE |