CVE-2024-56074
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
15/12/2024
Last modified:
16/12/2024
Description
gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/cyclotruc/gitingest/blob/9996a06a94450497c1abb35997f5e6cbc9b571ff/src/ingest.py#L22-L30
- https://github.com/cyclotruc/gitingest/blob/9996a06a94450497c1abb35997f5e6cbc9b571ff/src/ingest.py#L99-L100
- https://github.com/cyclotruc/gitingest/commit/9996a06a94450497c1abb35997f5e6cbc9b571ff
- https://github.com/cyclotruc/gitingest/pull/23
- https://gitingest.com/