The git-changelog utility in git-extras 1.7.0 allows...
Low severity
Unreviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jan 28, 2020
Published to the GitHub Advisory Database
Apr 23, 2022
Last updated
Jan 27, 2023
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
References