← voltar
CVE-2024-51990

Path traversal via crafted Git repositories in jj

CVSS 9.3 CRITICALEPSS 0.6%CWE-22
jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable to upgrade should avoid cloning repos from unknown sources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
martinvonz · jj

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →