QID 376677

Date Published: 2022-06-22

QID 376677: Git For Windows Security Vulnerability

Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency.

CVE-2021-46101: In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.

Affected Version:
Git for windows version prior to 2.35.0

QID Detection Logic (Authenticated): Windows: Checks for git-cmd.exe version using registry "HKLM\SOFTWARE\GitForWindows" and flag if found vulnerable.

Successful exploitation of this vulnerability may affect the integrity of the user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to update to latest version of git.
    Vendor References

    CVEs related to QID 376677

    Software Advisories
    Advisory ID Software Component Link
    Git Downloads URL Logo git-scm.com/download/win