First published: Fri Feb 11 2022(Updated: )
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Git Git-shell | <=2.35.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24975 is a vulnerability in Git through version 2.35.1 that affects the --mirror documentation and could lead to information disclosure.
CVE-2022-24975 has a severity rating of high with a CVSS score of 7.5.
CVE-2022-24975 affects the --mirror documentation in Git through version 2.35.1, potentially exposing deleted content and presenting a security risk for information disclosure.
To mitigate the risk of CVE-2022-24975, it is recommended to update to a version of Git that is not affected by the vulnerability, or apply any patches or fixes provided by the Git project.
More information about CVE-2022-24975 can be found in the references provided: [GitHub](https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191) and [Nightwatch Cybersecurity](https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/).