CVE-2021-46101: High severity git for windows vulnerability
Published Jan 31, 2022
·Updated
In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
Affected Software
1 affected component
Gitforwindows Git Windows<=2.34.1
Event History
Jan 31, 2022
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Git for Windows vulnerability?
The vulnerability ID for this Git for Windows vulnerability is CVE-2021-46101.
2
What is the severity level of CVE-2021-46101?
The severity level of CVE-2021-46101 is high, with a severity value of 7.5.
3
How does CVE-2021-46101 affect Git for Windows?
CVE-2021-46101 affects Git for Windows versions up to and including 2.34.1.
4
What is the impact of CVE-2021-46101?
CVE-2021-46101 allows an attacker to run git.cmd directly on the local repository when using git pull to update.
5
Is there a fix available for CVE-2021-46101?
Yes, updating to version 2.34.2 or later of Git for Windows will fix CVE-2021-46101.