Junglewise Threat Intelligence

CVE-2024-35197: RUSTSEC-2024-0352 - Refs and paths with reserved Windows device names access the devices

CVE-2024-35197 · Severity: low · CVSS 3.1 · Published 2024-05-22

Technologies: gitoxide-core (crates.io), gix-worktree (crates.io), gix (crates.io), gix-worktree-state (crates.io), gitoxide (crates.io), gix-index (crates.io). Vendors: crates.io.

Executive brief

Refs and paths with reserved Windows device names access the devices

Affected products

  • crates.io gitoxide-core
  • crates.io gix-ref
  • crates.io gix-worktree
  • crates.io gix
  • crates.io gix-worktree-state
  • crates.io gitoxide
  • crates.io gix-index

Related threats