QID 377914

Date Published: 2023-01-19

QID 377914: Git Remote Code Execution (RCE) Vulnerability

Git is a revision control system, a tool to manage your source code history.

Affected Versions:
Git versions prior to 2.39.1
QID Detection Logic (authenticated):
Windows: This QID checks for vulnerable file version of git-cmd.exe.

Depending on the vulnerability being exploited, an attackers can exploit this issue to obtain sensitive information or execute arbitrary code on a targeted system.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to upgrade to Git 2.39.1 or later versions to remediate these vulnerabilities.

    CVEs related to QID 377914

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v4px-mx59-w99c URL Logo github.com/git-for-windows/git/security/advisories/GHSA-v4px-mx59-w99c