漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit this. The ext command will be run if the repository is recursively cloned or if submodules are updated. This attack works when cloning both local and remote repositories.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
git-fastclone 安全漏洞
Vulnerability Description
git-fastclone是一套用于克隆git的工具。 git-fastclone 1.0.1之前的版本中存在安全漏洞,该漏洞源于程序执行来自.gitmodules的任意shell命令。攻击者可通过指示用户运行递归克隆利用该漏洞执行任意shell命令。
CVSS Information
N/A
Vulnerability Type
N/A