CVE-2021-28955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
22/03/2021
Last modified:
20/05/2022

Description

git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:git-bug_project:git-bug:*:*:*:*:*:*:*:* 0.7.2 (excluding)