CVE-2022-24765: Uncontrolled search for the Git directory in Git for Windows

Published Apr 8, 2022
·
Updated

A vulnerability was found in Git. This flaw occurs due to Git not checking the ownership of directories in a local multi-user system when running commands specified in the local repository configuration. This allows the owner of the repository to cause arbitrary commands to be executed by other users who access the repository.

Other sources

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder C:\.git, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set GITPS1SHOWDIRTYSTATE are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in C:\.git\config. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder .git on all drives where Git commands are run, and remove read/write access from those folders as a workaround. Alternatively, define or extend GITCEILINGDIRECTORIES to cover the parent directory of the user profile, e.g. C:\Users if the user profile is located in C:\Users\my-user-name.

Git. A logic issue was addressed with improved state management.

On multi-user machines, Git users might find themselves unexpectedly in a Git worktree, e.g. when there is a scratch space (/scratch/) intended for all users and another user created a repository in /scratch/.git. Merely having a Git-aware prompt that runs git status (or git diff) and navigating to a directory which is supposedly not a Git worktree, or opening such a directory in an editor or IDE such as VS Code or Atom, will potentially run commands defined by that other user via /scratch/.git/config.

Red Hat

Credit

俞晨东

Affected Software

20 affected componentsFixes available
redhat/git<0:2.39.1-1.el8
0:2.39.1-1.el8
redhat/git<0:2.39.1-1.el9
0:2.39.1-1.el9
redhat/git<2.30.3
2.30.3
redhat/git<2.31.2
2.31.2
redhat/git<2.32.1
2.32.1
redhat/git<2.33.2
2.33.2
redhat/git<2.34.2
2.34.2
redhat/git<2.35.2
2.35.2
redhat/and git<2.36.0
2.36.0
Apple Xcode<13.4
13.4
All of the following
Microsoft Windows
git-scm Git<2.35.2
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Apple Xcode<13.4
Debian Debian Linux=10.0
git-scm Git<2.35.2
Microsoft Windows

Event History

Apr 8, 2022
Data Sourced
via Red Hat·12:41 PM
DescriptionSeverityAffected Software
Apr 12, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-24765?

CVE-2022-24765 is a logic issue in Git that has been addressed with improved state management.

2

Who does the vulnerability CVE-2022-24765 affect?

The vulnerability affects users working on multi-user machines where untrusted parties have write access to the same hard disk.

3

How can the vulnerability CVE-2022-24765 be exploited?

Untrusted parties could create the folder `C:\.git` on the affected machine, which would be picked up by Git operations.

4

What is the severity of CVE-2022-24765?

CVE-2022-24765 has a severity rating of 7.8 (High).

5

How can I fix the vulnerability CVE-2022-24765?

The vulnerability can be fixed by updating Git to version 2.30.3 or above.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203