CVE-2021-29468

Severity
8.8HIGH
EPSS
0.5%
top 32.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 29

Description

Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that contains symbolic links as well as files with backslash characters in the file name may cause just-checked out code to be executed while checking out a repository using Git on Cygwin. The problem will be patched in the Cygwin Git v2.31.1-2 release. At time of writing, the vulnerability is present in the upstream Git source code; any Cygwin user who compiles Git for themselves f

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5me-and/cygwin-git< 2.31.1-2
NVDcygwin/git2.31.1-1
Alpinegit< 0+13

Patches

🔴Vulnerability Details

2
OSV
CVE-2021-29468: Cygwin Git is a patch set for the git command line tool for the cygwin environment2021-04-29
CVEList
Arbitrary code execution when checking out an attacker-controlled Git branch2021-04-29
CVE-2021-29468 (HIGH CVSS 8.8) | Cygwin Git is a patch set for the g | cvebase.io