CVE-2022-24765
Summary
| CVE | CVE-2022-24765 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-12 18:15:00 UTC |
| Updated | 2023-12-27 10:15:00 UTC |
| Description | Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access from those folders as a workaround. Alternatively, define or extend `GIT_CEILING_DIRECTORIES` to cover the _parent_ directory of the user profile, e.g. `C:\Users` if the user profile is located in `C:\Users\my-user-name`. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Git - git Documentation |
MISC |
git-scm.com |
|
| [SECURITY] Fedora 37 Update: libgit2-1.3.2-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: git-2.37.1-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: rust-cargo-c-0.9.12-3.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: git-2.35.3-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: git-2.34.3-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: libgit2-1.3.2-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: libgit2-1.3.2-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: rust-bat-0.21.0-6.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Git - Git in Bash |
MISC |
git-scm.com |
|
| [SECURITY] [DLA 3239-1] git security update |
MLIST |
lists.debian.org |
|
| oss-security - git v2.35.2 and friends for CVE-2022-24765 |
MLIST |
www.openwall.com |
|
| Git: Multiple Vulnerabilities (GLSA 202312-15) — Gentoo security |
|
security.gentoo.org |
|
| [SECURITY] Fedora 36 Update: git-2.37.1-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: rust-bat-0.21.0-6.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: git-2.36.0-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: git-2.37.1-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Full Disclosure: APPLE-SA-2022-05-16-8 Xcode 13.4 |
FULLDISC |
seclists.org |
|
| About the security content of Xcode 13.4 - Apple Support |
CONFIRM |
support.apple.com |
|
| [SECURITY] Fedora 35 Update: git-2.37.1-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: libgit2-1.3.2-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: rust-cargo-c-0.9.12-3.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: git-2.36.0-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: git-2.34.3-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Uncontrolled search for the Git directory in Git for Windows · Advisory · git-for-windows/git · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 35 Update: git-2.35.3-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160630 Oracle Enterprise Linux Security Update for git (ELSA-2023-2319)
- 160657 Oracle Enterprise Linux Security Update for git (ELSA-2023-2859)
- 181320 Debian Security Update for git (DLA 3239-1)
- 181321 Debian Security Update for git (DLA 3239-2)
- 181518 Debian Security Update for git (DSA 5332-1)
- 183677 Debian Security Update for git (CVE-2022-24765)
- 198738 Ubuntu Security Notification for Git Vulnerability (USN-5376-1)
- 198769 Ubuntu Security Notification for Git Vulnerability (USN-5376-2)
- 241436 Red Hat Update for git (RHSA-2023:2319)
- 241487 Red Hat Update for git (RHSA-2023:2859)
- 242859 Red Hat Update for git (RHSA-2024:0407)
- 282662 Fedora Security Update for git (FEDORA-2022-2fec5f30be)
- 282663 Fedora Security Update for git (FEDORA-2022-3759ebabd2)
- 282953 Fedora Security Update for git (FEDORA-2022-dfd7e7fc0e)
- 282985 Fedora Security Update for git (FEDORA-2022-2a5de7cb8b)
- 283637 Fedora Security Update for libgit2 (FEDORA-2023-470c7ea49e)
- 283645 Fedora Security Update for rust (FEDORA-2023-e3c8abd37e)
- 283646 Fedora Security Update for libgit2 (FEDORA-2023-1068309389)
- 283652 Fedora Security Update for rust (FEDORA-2023-3ec32f6d4e)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 296086 Oracle Solaris 11.4 Support Repository Update (SRU) 51.132.1 Missing (CPUOCT2022)
- 353952 Amazon Linux Security Advisory for git : ALAS-2022-1589
- 353980 Amazon Linux Security Advisory for git : ALAS2-2022-1810
- 354348 Amazon Linux Security Advisory for git : ALAS2022-2022-067
- 354445 Amazon Linux Security Advisory for git : ALAS2022-2022-236
- 354589 Amazon Linux Security Advisory for git : ALAS-2022-236
- 355256 Amazon Linux Security Advisory for git : ALAS2023-2023-065
- 376606 Apple Xcode Prior to 13.4 Vulnerability (HT213261)
- 501412 Alpine Linux Security Update for git
- 501742 Alpine Linux Security Update for git
- 501961 Alpine Linux Security Update for git
- 502219 Alpine Linux Security Update for git
- 502876 Alpine Linux Security Update for libgit2
- 503967 Alpine Linux Security Update for git
- 671833 EulerOS Security Update for git (EulerOS-SA-2022-1888)
- 671902 EulerOS Security Update for git (EulerOS-SA-2022-1929)
- 671916 EulerOS Security Update for git (EulerOS-SA-2022-1995)
- 671942 EulerOS Security Update for git (EulerOS-SA-2022-1965)
- 671969 EulerOS Security Update for git (EulerOS-SA-2022-2156)
- 672001 EulerOS Security Update for git (EulerOS-SA-2022-2131)
- 710816 Gentoo Linux Git Multiple Vulnerabilities (GLSA 202312-15)
- 752045 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:1260-1)
- 752066 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:1306-1)
- 752096 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:1484-1)
- 752375 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:2535-1)
- 752381 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:2537-1)
- 752392 SUSE Enterprise Linux Security Update for git (SUSE-SU-2022:2550-1)
- 752650 SUSE Enterprise Linux Security Update for libgit2 (SUSE-SU-2022:3494-1)
- 752654 SUSE Enterprise Linux Security Update for libgit2 (SUSE-SU-2022:3495-1)
- 753386 SUSE Enterprise Linux Security Update for libgit2 (SUSE-SU-2022:3283-1)
- 91881 Microsoft Visual Studio Security Update for April 2022
- 941032 AlmaLinux Security Update for git (ALSA-2023:2319)
- 941077 AlmaLinux Security Update for git (ALSA-2023:2859)