QID 376576
Date Published: 2022-05-04
QID 376576: Git LFS Remote Code Execution (RCE) Vulnerability (CVE-2022-24826)
Git is a revision control system, a tool to manage your source code history.
On Windows, if Git LFS operates on a malicious repository with a '..exe' file as well as a file named 'git.exe', and 'git.exe' is not found in 'PATH', the '..exe' program will be executed, permitting the attacker to execute arbitrary code.
Affected Versions:
Git LFS for Windows version from 2.12.1 prior to 3.1.3
NOTE:
This does not affect Unix systems.
QID Detection Logic:(Authenticated)
It checks for git-lfs.exe file version from HKLM\SYSTEM\ControlSet001\Control\Session Manager\Environment registry.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to Git for Windows 3.1.3 or 3.1.4 or later versions to remediate this vulnerability.
For more information please visithere
Vendor References
- Git LFS Advisory -
github.com/git-lfs/git-lfs/security/advisories/GHSA-6rw3-3whw-jvjj
CVEs related to QID 376576
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Git LFS Advisory |
|