Advisory #17
Titlebit arbitrary code execution via malicious repository
CVE IDCVE-2021-28954
VendorChris Walz
Affected productbit
Affected versions- 1.0.4
Vulnerability typeCWE-427 (Uncontrolled Search Path Element)
Descriptionbit for Windows has a vulnerability that allows the malicious repository to hijack git executable, which leads arbitrary code execution.
StatusFixed in 1.0.5
RecommendationUpdate to 1.0.5 or above