CVE-2025-22620

CVSS 3.1 Score 5.0 of 10 (medium)

Details

Published Jan 20, 2025
CWE ID 281
CWE ID 687

Summary

CVE-2025-22620 affects the gitoxide implementation of Git written in Rust. Before version 0.17.0, gix-worktree-state incorrectly set world-writable permissions on executable files during checkout, intending for the umask to restrict access. However, one of the strategies used to set permissions is not subject to the umask, resulting in the files retaining world-writable permissions in certain scenarios. This vulnerability has been addressed in version 0.17.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share