Vulnerability in gitoxide's Rust Implementation of Git Affecting Git Operations
CVE-2024-43785

Currently unrated

Key Information:

Vendor

Byron

Status
Vendor
CVE Published:
22 August 2024

What is CVE-2024-43785?

The gitoxide project, known for its fast and secure Rust implementation of Git, has a vulnerability that arises from its failure to neutralize special characters such as newlines, backspaces, and control characters, including ANSI escape sequences, in various repository elements. This oversight can lead to untrusted repositories being able to manipulate their contents or mislead users by altering error messages, potentially compromising the integrity of Git operations and user interactions.

References

Timeline

  • Vulnerability published

.