CVE-2024-21531

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 78

Summary

CVE-2024-21531 is a new vulnerability affecting the git-shallow-clone package. This issue permits attackers to inject commands due to insufficient sanitization or mitigation in the process variable within the gitShallowClone function. Successful exploitation could result in unauthorized control over the affected system or exposure of sensitive information. Users are strongly advised to update their git-shallow-clone packages to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share