跳转到帖子

GitLens Git Local Configuration Exec

recommended_posts

发布于
  • Members

GitLens Git Local Configuration Exec

Disclosed
11/14/2023
Created
04/19/2024

Description

GitKraken GitLens before v.14.0.0 allows an untrusted workspace to execute git commands. A repo may include its own .git folder including a malicious config file to execute arbitrary code. Tested against VSCode 1.87.2 with GitLens 13.6.0 on Ubuntu 22.04 and Windows 10

Author(s)

  • h00die
  • Paul Gerste

Architectures

cmd

Development

  • Source Code
  • History
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…