GHSA-7w47-3wg8-547c
HIGHCVE-2024-35186During checkout, gitoxide does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application.
- Affected
- >=0.0.0-0, <0.11.0
- Fixed in
- 0.33.0
- Weakness
- CWE-22
- Published
- 2024-05-22
- Source
- github