Vulnerability Description
The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://crates.io/crates/gix-transport
- https://github.com/GitoxideLabs/gitoxide/pull/1032
- https://github.com/advisories/GHSA-rrjw-j4m2-mf34
- https://rustsec.org/advisories/RUSTSEC-2023-0064.html
FAQ
What is CVE-2023-53158?
CVE-2023-53158 is a vulnerability with a CVSS score of 4.1 (MEDIUM). The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnera...
How severe is CVE-2023-53158?
CVE-2023-53158 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53158?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.