QID 378458

Date Published: 2023-05-08

QID 378458: Git for Windows Multiple Security Vulnerability

The Git for Windows is a build environment that includes all the tools necessary for developers who want to contribute by writing code for Git for Windows.

Affected Versions:
git-for-windows prior to 2.40.1
QID Detection Logic:(Authenticated)
It checks for a vulnerable version of Git in the registry key.

Successful exploitation of the vulnerability may lead to multiple execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 3.6 severity.
  • Solution
    The vendor has released a patch for these vulnerabilities. For more information, please visit GHSA-9w66GHSA-g4fvGHSA-gq5x

    CVEs related to QID 378458

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9w66 URL Logo github.com/git-for-windows/git/security/advisories/GHSA-9w66-8mq8-5vm8
    GHSA-g4fv URL Logo github.com/git-for-windows/git/security/advisories/GHSA-g4fv-xjqw-q7jm
    GHSA-gq5x URL Logo github.com/git-for-windows/git/security/advisories/GHSA-gq5x-v87v-8f7g