QID 379406

Date Published: 2024-02-26

QID 379406: Git for Windows Multiple Security Vulnerability (CVE-2022-29187,CVE-2022-31012)

The Git for Windows is a build environment that includes all the tools necessary for developers who want to contribute by writing code for Git for Windows.

Affected Versions:
git-for-windows prior to 2.37.1

QID Detection Logic:(Authenticated)
It checks for a vulnerable version of Git in the registry key.

Successful exploitation of the vulnerability may lead to multiple execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    The vendor has released a patch for these vulnerabilities. For more information, please visit v2.37.1

    CVEs related to QID 379406

    Software Advisories
    Advisory ID Software Component Link
    v2.37.1 URL Logo github.com/git-for-windows/git/releases/tag/v2.37.1.windows.1