CVE-2024-51990

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable to upgrade should avoid cloning repos from unknown sources.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Nov 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 01:15

Updated : 2024-11-08 19:01


NVD link : CVE-2024-51990

Mitre link : CVE-2024-51990


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')