Vulnerability Report: GO-2021-0098
- CVE-2021-21237, GHSA-cx3w-xqmc-84g5
- Affects: github.com/git-lfs/git-lfs
- Published: Apr 14, 2021
- Modified: May 20, 2024
Due to the standard library behavior of exec.LookPath on Windows a number of methods may result in arbitrary code execution when cloning or operating on untrusted Git repositories.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.5.1-0.20210113180018-fc664697ed2c
-
before v1.5.1-0.20210113180018-fc664697ed2c
-
before v1.5.1-0.20210113180018-fc664697ed2c
-
before v1.5.1-0.20210113180018-fc664697ed2c
Aliases
References
- https://github.com/git-lfs/git-lfs/commit/fc664697ed2c2081ee9633010de0a7f9debea72a
- https://vuln.go.dev/ID/GO-2021-0098.json
Credits
- @Ry0taK
Feedback
See anything missing or incorrect?
Suggest an edit to this report.