« Volver al listado

CVE-2023-53158

Estado: AplazadaMedia (4.1)—

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53158",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-53158",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-28T17:23:53.586851Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.1,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "GitoxideLabs",
          "product": "gix-transport",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.36.1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-28T01:15:24.837",
  "references": [
    {
      "url": "https://crates.io/crates/gix-transport",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/GitoxideLabs/gitoxide/pull/1032",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/advisories/GHSA-rrjw-j4m2-mf34",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://rustsec.org/advisories/RUSTSEC-2023-0064.html",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The gix-transport crate before 0.36.1 for Rust allows command execution via the \"gix clone 'ssh://-oProxyCommand=open$IFS\" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit."
    },
    {
      "lang": "es",
      "value": "El paquete gix-transport para Rust, anterior a la versión 0.36.1, permite la ejecución de comandos mediante la subcadena \"gix clone 'ssh://-oProxyCommand=open$IFS\". NOTA: Esto se descubrió antes de CVE-2024-32884, una vulnerabilidad similar (que afecta a un campo de nombre de usuario) y que es más difícil de explotar."
    }
  ],
  "lastModified": "2026-06-17T06:44:24.643",
  "sourceIdentifier": "cve@mitre.org"
}