CVE-2024-21533
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 88
Summary
CVE-2024-21533 is a newly disclosed vulnerability affecting all versions of the ggit package. The issue stems from an Arbitrary Argument Injection vulnerability in the clone() API. Malicious users can exploit this weakness by specifying a remote URL and a file on disk to clone to, bypassing input sanitization and validation checks. The library fails to recognize double-dash POSIX characters (--) as the end of command-line options when communicating with the git binary, potentially leading to unintended consequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.