QID 376677
Date Published: 2022-06-22
QID 376677: Git For Windows Security Vulnerability
Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency.
CVE-2021-46101: In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
Affected Version:
Git for windows version prior to 2.35.0
QID Detection Logic (Authenticated): Windows: Checks for git-cmd.exe version using registry "HKLM\SOFTWARE\GitForWindows" and flag if found vulnerable.
Successful exploitation of this vulnerability may affect the integrity of the user.
Solution
Customers are advised to update to latest version of git.
Vendor References
- Git Downloads -
git-scm.com/download/win
CVEs related to QID 376677
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Git Downloads |
|