216.73.216.233

CVE-2025-22620

· Published 20/01/2025 16:15 · Modified 20/01/2025 16:15

Labels: CVE-2025-22620 2025-01-20CVE-2025-22620CWE-281[email protected]

Essential information

Published
20/01/2025 16:15
Modified
20/01/2025 16:15
Author
Creator
CVSS
5.0 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

CVSS metrics

Description

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a repository to be world-writable in some situations. This vulnerability is fixed in 0.17.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References