GHSA-5c5j-jmhx-q2gr: Duplicate Advisory: gix-transport code execution vulnerability
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rrjw-j4m2-mf34. This link is maintained to preserve external references.
Original Description
The gix-transport crate before 0.36.1 for Rust allows command execution via the “gix clone ‘ssh://-oProxyCommand=open$IFS” substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.
References
Code Behaviors & Features
Detect and mitigate GHSA-5c5j-jmhx-q2gr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →