Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-57q7-rxqq-7vgp
No affected components available
Impact
On Windows, if git-sizer is run against a non-bare repository, and that repository has an executable called git.exe, git.bat, etc., then that executable might be run by git-sizer rather than the system git executable. An attacker could try to use social engineering to get a victim to run git-sizer against a hostile repository and thereby get the victim to run arbitrary code.
On Linux or other Unix-derived platforms, a similar problem could occur if the user's PATH has the current directory before the path to the standard git executable, but this is would be a very unusual configuration that has been known for decades to lead to all kinds of security problems.
Patches
Users should update to git-sizer v1.4.0
Workarounds
If you are on Windows, then either
- Don't run
git-sizeragainst a repository that might contain hostile code, or, if you must… - Run
git-sizeragainst a bare clone of the hostile repository, or, if that is not possible… - Make sure that the hostile repository doesn't have an executable in its top-level directory before running
git-sizer.
If you are on Linux or other Unix-based system, then (for myriad reasons!) don't add the current directory to your PATH.
References
For more information
If you have any questions or comments about this advisory:
- Open an issue in the
git-sizerproject. - Email us at GitHub support.
Measures severity based on intrinsic characteristics of the vulnerability, independent of environment.
No exploitation activity has been observed at this time. Continue routine monitoring.
Probability that this vulnerability will be exploited in the wild within the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard