QID 377913

Date Published: 2023-01-19

QID 377913: Git Multiple Security Vulnerabilities

Git is a revision control system, a tool to manage your source code history.

Affected Versions:
Git 2.30.x prior to 2.30.7
Git 2.31.x prior to 2.31.6
Git 2.32.x prior to 2.32.5
Git 2.33.x prior to 2.33.6
Git 2.34.x prior to 2.34.6
Git 2.35.x prior to 2.35.6
Git 2.36.x prior to 2.36.4
Git 2.37.x prior to 2.37.5
Git 2.38.x prior to 2.38.3
Git 2.39.x prior to 2.39.1

QID Detection Logic (authenticated):
Windows: This QID checks for vulnerable version of git-cmd.exe.
Linux/MacOS: This QID checks for vulnerable version via git --version.

An attacker can trigger remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Git v2.30.7, v2.31.6, v2.32.5, v2.33.6, v2.34.6, v2.35.6, v2.36.4, v2.37.5, v2.38.3, v2.39.1 or later versions to remediate these vulnerabilities.

    CVEs related to QID 377913

    Software Advisories
    Advisory ID Software Component Link
    GHSA-475x-2q3q-hvwq URL Logo github.com/git/git/security/advisories/GHSA-475x-2q3q-hvwq
    GHSA-c738-c5qq-xg89 URL Logo github.com/git/git/security/advisories/GHSA-c738-c5qq-xg89