CNNVD-202507-1041 Information

CNNVD ID

CNNVD-202507-1041

CVE-2025-48384

  • CNNVD Published: 2025-07-08

Description (Chinese)

Git是Git开源的一套免费、开源的分布式版本控制系统。 Git存在安全漏洞,该漏洞源于在处理配置值时尾随回车符的处理不当,可能使子模块被错误检出到由符号链接指向的钩子目录,意外执行其中的可执行脚本。

Description (English)

Git is a free, open source distributed version control system for Git open source. Git has a security loophole, which stems from the inappropriate handling of back-to-back vehicles while processing configuration values, which may result in the submodule being wrongly detected into the hook directory to which the symbol link points and accidentally executes the enforceable script.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

git-annex

Published

2025-07-08

Last Modified

2026-02-24

References

https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9 https://access.redhat.com/security/cve/cve-2025-48384 https://nvd.nist.gov/vuln/detail/CVE-2025-48384 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48384

Patch

https://git-scm.com/

Share on: