Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NDefault status
unaffected
1.8.10.0 (semver) before 2.19.0
affected
Description
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
Problem types
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Product status
1.8.10.0 (semver) before 2.19.0
Credits
Gabriele Paris of NATO Cyber Security Centre
References
gitlab.com/...ommit/7052e3ef61cd104f8a90fb3dcdfb403cbc8c1773