CVE-2021-36376: Relative Path Traversal in git-delta
(updated )
git-delta before 0.8.3 on Windows resolves an executable’s pathname as a relative path from the current directory.
References
- github.com/advisories/GHSA-5xg3-j2j6-rcx4
- github.com/dandavison/delta
- github.com/dandavison/delta/commit/f01846bd443aaf92fdd5ac20f461beac3f6ee3fd
- github.com/dandavison/delta/releases/tag/0.8.3
- nvd.nist.gov/vuln/detail/CVE-2021-36376
- rustsec.org/advisories/RUSTSEC-2021-0105.html
- vuln.ryotak.me/advisories/54
Detect and mitigate CVE-2021-36376 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →