• CVE-2025-46835

发布时间: 2025年7月18日

修改时间: 2025年7月18日

概要

A vulnerability was found in j6t git-gui up to 2.50.0 (Versioning Software). It has been rated as critical.Using CWE to declare the problem leads to CWE-88. The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.Impacted is confidentiality, integrity, and availability.The vulnerability scanner Nessus provides a plugin with the ID 241644 (FreeBSD : git -- multiple vulnerabilities (2a4472ed-5c0d-11f0-b991-291fce777db8)), which helps to determine the existence of the flaw in a target environment.Upgrading to version 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1 or 2.50.1 eliminates this vulnerability.The vulnerability is also documented in the vulnerability database at Tenable (241644).

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Local
CVSS评分 N/A 8.5
Attack Complexity Low
Privileges Required None
Scope Changed
Integrity High
User Interaction Required
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2716 git security update 2025年8月1日

影响产品

产品 状态
KY3.4-5 git Fixed
V6 git Fixed
KY3.5.3 git Fixed
KY3.5.2 git Fixed