{"id":"AZL-66020","summary":"CVE-2023-53158 affecting package rust for versions less than 1.72.0-8","details":"The gix-transport crate before 0.36.1 for Rust allows command execution via the \"gix clone 'ssh://-oProxyCommand=open$IFS\" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.","modified":"2026-04-21T04:37:45.046066Z","published":"2025-07-28T01:15:24Z","upstream":["CVE-2023-53158"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53158"}],"affected":[{"package":{"name":"rust","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/rust"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.72.0-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66020.json"}}],"schema_version":"1.7.5"}