CVE-2024-51990

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the clone. This issue has been addressed in version 0.23.0. Users are advised to upgrade. Users unable to upgrade should avoid cloning repos from unknown sources.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-11-07 01:15

Updated : 2024-11-08 19:01


NVD link : CVE-2024-51990

Mitre link : CVE-2024-51990

CVE.ORG link : CVE-2024-51990


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')