7.8
CWE
427
Advisory Published
CVE Published
Updated

CVE-2022-24765: Uncontrolled search for the Git directory in Git for Windows

First published: Fri Apr 08 2022(Updated: )

A vulnerability was found in Git. This flaw occurs due to Git not checking the ownership of directories in a local multi-user system when running commands specified in the local repository configuration. This allows the owner of the repository to cause arbitrary commands to be executed by other users who access the repository.

Credit: 俞晨东 security-advisories@github.com security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
redhat/git<2.30.3
2.30.3
redhat/git<2.31.2
2.31.2
redhat/git<2.32.1
2.32.1
redhat/git<2.33.2
2.33.2
redhat/git<2.34.2
2.34.2
redhat/git<2.35.2
2.35.2
redhat/and git<2.36.0
2.36.0
redhat/git<0:2.39.1-1.el8
0:2.39.1-1.el8
redhat/git<0:2.39.1-1.el9
0:2.39.1-1.el9
All of
<2.35.2
=34
=35
=36
=37
<13.4
=10.0
Git-scm Git<2.35.2
Microsoft Windows
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Apple Xcode<13.4
Debian Debian Linux=10.0
Apple Xcode<13.4
13.4

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Parent vulnerabilities

(Appears in the following advisories)

Peer vulnerabilities

(Found alongside the following vulnerabilities)

Frequently Asked Questions

  • What is CVE-2022-24765?

    CVE-2022-24765 is a logic issue in Git that has been addressed with improved state management.

  • Who does the vulnerability CVE-2022-24765 affect?

    The vulnerability affects users working on multi-user machines where untrusted parties have write access to the same hard disk.

  • How can the vulnerability CVE-2022-24765 be exploited?

    Untrusted parties could create the folder `C:\.git` on the affected machine, which would be picked up by Git operations.

  • What is the severity of CVE-2022-24765?

    CVE-2022-24765 has a severity rating of 7.8 (High).

  • How can I fix the vulnerability CVE-2022-24765?

    The vulnerability can be fixed by updating Git to version 2.30.3 or above.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203