CVE-2021-28955

CRITICAL

Git-bug < 0.7.2 - Uncontrolled Search Path

Title source: rule

Description

git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in certain PATH situations (most often seen on Windows).

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (2)

git-bug_project/git-bug < 0.7.2
MichaelMure/git-bug < 0.7.2Go

Timeline

Published Mar 22, 2021
Tracked Since Feb 18, 2026