{"id":"GHSA-m4ch-rfv5-x5g3","summary":"git2-rs fails to verify SSH keys by default","details":"The git2 and libgit2-sys crates are Rust wrappers around the [libgit2](https://libgit2.org/) C library. It was discovered that libgit2 1.5.0 and below did not verify SSH host keys when establishing an SSH connection, exposing users of the library to Man-In-the-Middle attacks.\n\nThe libgit2 team assigned [CVE-2023-22742](https://github.com/libgit2/libgit2/security/advisories/GHSA-8643-3wh5-rmjq) to this vulnerability. The following versions of the libgit2-sys Rust crate have been released:\n\n* libgit2-sys 0.14.2, updating the underlying libgit2 C library to version 1.5.1.\n* libgit2-sys 0.13.5, updating the underlying libgit2 C library to version 1.4.5.\n\nA new git2 crate version has also been released, 0.16.1. This version only bumps its libgit2-sys dependency to ensure no vulnerable libgit2-sys versions are used, but contains no code changes: if you update the libgit2-sys version there is no need to also update the git2 crate version.\n\n[You can learn more about this vulnerability in libgit2's advisory](https://github.com/libgit2/libgit2/security/advisories/GHSA-8643-3wh5-rmjq)","aliases":["CVE-2023-22742","GHSA-8643-3wh5-rmjq","RUSTSEC-2023-0003"],"modified":"2023-11-01T05:19:29.489019Z","published":"2023-01-20T23:36:41Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-20T23:36:41Z"},"references":[{"type":"WEB","url":"https://github.com/libgit2/libgit2/security/advisories/GHSA-8643-3wh5-rmjq"},{"type":"WEB","url":"https://github.com/rust-lang/git2-rs/security/advisories/GHSA-m4ch-rfv5-x5g3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22742"},{"type":"WEB","url":"https://github.com/rust-lang/git2-rs/commit/87934f87d36753ed702792ec063be7246444a8e1"},{"type":"PACKAGE","url":"https://github.com/rust-lang/git2-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0003.html"}],"affected":[{"package":{"name":"libgit2-sys","ecosystem":"crates.io","purl":"pkg:cargo/libgit2-sys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.14.0"},{"fixed":"0.14.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-m4ch-rfv5-x5g3/GHSA-m4ch-rfv5-x5g3.json"}},{"package":{"name":"libgit2-sys","ecosystem":"crates.io","purl":"pkg:cargo/libgit2-sys"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-m4ch-rfv5-x5g3/GHSA-m4ch-rfv5-x5g3.json"}},{"package":{"name":"git2","ecosystem":"crates.io","purl":"pkg:cargo/git2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.16.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-m4ch-rfv5-x5g3/GHSA-m4ch-rfv5-x5g3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}