Home
MEDIUM: 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:LDefault status
unknown
2.6.1 (semver)
affected
Description
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
Problem types
CWE-377 Insecure Temporary File
Product status
2.6.1 (semver)
References
github.com/magicmonty/bash-git-prompt/issues/561