Search CVE reports
21 – 30 of 45072 results
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because...
1 affected package
rust-gix-transport
| Package | 24.04 LTS |
|---|---|
| rust-gix-transport | Needs evaluation |
Not in release
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to...
1 affected package
rust-gix-pack
| Package | 24.04 LTS |
|---|---|
| rust-gix-pack | Not in release |
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via...
2 affected packages
rust-gix, rust-gix-validate
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
| rust-gix-validate | Needs evaluation |
Not in release
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked...
1 affected package
rust-gix
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
Not in release
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to...
1 affected package
rust-gix
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band...
1 affected package
rust-gix-packetline
| Package | 24.04 LTS |
|---|---|
| rust-gix-packetline | Needs evaluation |
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and...
1 affected package
rust-gix-credentials
| Package | 24.04 LTS |
|---|---|
| rust-gix-credentials | Needs evaluation |
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization...
4 affected packages
rust-gix, rust-gix-features, rust-gix-worktree, rust-gix-worktree-state
| Package | 24.04 LTS |
|---|---|
| rust-gix | Not in release |
| rust-gix-features | Needs evaluation |
| rust-gix-worktree | Not in release |
| rust-gix-worktree-state | Not in release |
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect...
2 affected packages
rust-gix-transport, rust-gix-url
| Package | 24.04 LTS |
|---|---|
| rust-gix-transport | Needs evaluation |
| rust-gix-url | Needs evaluation |
Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
1 affected package
chromium-browser
| Package | 24.04 LTS |
|---|---|
| chromium-browser | Not affected |