Improper Resolution of Path Configuration Affecting gix-path package, versions <0.10.11


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-GIXPATH-7922571
  • published6 Sept 2024
  • disclosed6 Sept 2024
  • creditEliah Kagan

Introduced: 6 Sep 2024

CVE-2024-45405  (opens in a new tab)
CWE-41  (opens in a new tab)
First added by Snyk

How to fix?

Upgrade gix-path to version 0.10.11 or higher.

Overview

gix-path is a gitoxide project crate dealing paths and their conversions

Affected versions of this package are vulnerable to Improper Resolution of Path Configuration through the installation_config and installation_config_prefix functions. An attacker can execute arbitrary code by manipulating the path resolution process to inject malicious configuration.

CVSS Scores

version 4.0
version 3.1