CVE-2024-35186 Information
May 25, 2024
cve
Description
gitoxide is a pure Rust implementation of Git. During checkout gix-worktree-state does not verify that paths point to locations in the working tree. A specially crafted repository can when cloned place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality integrity and availability but creating files outside a working tree without attempting to execute code can directly impact integrity as well. This vulnerability has been patched in version(s) 0.36.0.
Reference
https://github.com/Byron/gitoxide/security/advisories/GHSA-7w47-3wg8-547c
Share on: