mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
18 lines
1.0 KiB
Markdown
18 lines
1.0 KiB
Markdown
### [CVE-2024-35186](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35186)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality, integrity, and availability, but creating files outside a working tree without attempting to execute code can directly impact integrity as well. This vulnerability has been patched in version(s) 0.36.0.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/Byron/gitoxide/security/advisories/GHSA-7w47-3wg8-547c
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|