9.8
CVE-2021-28955
- EPSS 0.47%
- Veröffentlicht 22.03.2021 07:15:12
- Zuletzt bearbeitet 21.11.2024 06:00:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Git-bug Project ≫ Git-bug Version < 0.7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.637 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.