An open API service providing security vulnerability metadata for many open source software ecosystems.

cargo

gitoxide

cargo · A command-line application for interacting with git repositories · Repository · Package

Moderate
6 months ago

gitoxide does not detect SHA-1 collision attacks GSA_kwCzR0hTQS0yZnJ4LTI1OTYteDVyNs4ABGbF

cargo gix-worktree-state, gix-worktree, gix-traverse, gix-status, gix-revwalk, gix-revision, gix-ref, gix-protocol, gix-negotiate, gix-merge, gix-fsck, gix-filter, gix-discover, gix-dir, gix-diff, gix-config, gix-blame, gix-archive, gix, gitoxide-core, gitoxide, gix-pack, gix-odb, gix-object, gix-index, gix-commitgraph, gix-features
Moderate
over 1 year ago

gix refs and paths with reserved Windows device names access the devices GSA_kwCzR0hTQS00OWpjLXI3ODgtM2ZjOc4AA8fX

cargo gix-ref, gix, gitoxide-core, gix-worktree, gitoxide, gix-worktree-state
High
over 1 year ago

gix traversal outside working tree enables arbitrary code execution GSA_kwCzR0hTQS03dzQ3LTN3ZzgtNTQ3Y84AA8fW

cargo gix-index, gitoxide-core, gix, gix-worktree, gix-fs, gitoxide, gix-worktree-state