VDB
GHSA-m4ch-rfv5-x5g3
GHSA-m4ch-rfv5-x5g3
PUBLISHED
CVSS 6.800000190734863 MEDIUM
git2-rs fails to verify SSH keys by default
Risk Scores
CVSS v3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| crates.io | ||
| crates.io | libgit2-sys | 0, 0.14.0, 0 |
| crates.io | git2 | 0, 0, 0 |
| crates.io | git2 | |
| crates.io | libgit2-sys |
Timeline
- Jan 20, 2023 CVE Published
- Jan 20, 2023 CVE Updated
- Mar 2, 2026 Security Advisory
References
- https://github.com/libgit2/libgit2/security/advisories/GHSA-8643-3wh5-rmjq url
- https://github.com/rust-lang/git2-rs/security/advisories/GHSA-m4ch-rfv5-x5g3 url
- https://nvd.nist.gov/vuln/detail/CVE-2023-22742 advisory
- https://github.com/rust-lang/git2-rs/commit/87934f87d36753ed702792ec063be7246444a8e1 url
- https://github.com/rust-lang/git2-rs package
- https://rustsec.org/advisories/RUSTSEC-2023-0003.html url
- GitHub Advisory GHSA-m4ch-rfv5-x5g3 vendor-advisory