gitoxide 的 gix-transport 在 0.59.2 版本之前,未能在 git-daemon 连接请求中过滤控制字符,使得攻击者可以通过构造的 Git URL 注入 NUL、CR 或 LF 字节。攻击者能够注入额外的以 NUL 分隔的协议字段,以伪造虚拟主机,或在 daemon 请求和日志中注入换行符。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GitoxideLabs | gitoxide | < 0.59.2 |
affected |
0.59.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitoxideLabs | gitoxide | 0 ~ 0.59.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet