CVE-2022-24765
published 2022-04-12CVE-2022-24765: Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.78%
52.2th percentile
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access from those folders as a workaround. Alternatively, define or extend `GIT_CEILING_DIRECTORIES` to cover the _parent_ directory of the user profile, e.g. `C:\Users` if the user profile is located in `C:\Users\my-user-name`.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.4 | 13.4 |
| apple | xcode | < 14.1 | 14.1 |
| apple | xcode | — | — |
| debian | debian_linux | — | — |
| debian | git | < git 1:2.37.2-1 (bookworm) | git 1:2.37.2-1 (bookworm) |
| debian | git | < git 1:2.35.2-1 (bookworm) | git 1:2.35.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| git-scm | git | < 2.35.2 | 2.35.2 |
| git-scm | git | >= 2.30.3 < 2.30.5 | 2.30.5 |
| git-scm | git | >= 2.31.2 < 2.31.4 | 2.31.4 |
| git-scm | git | >= 2.32.1 < 2.32.3 | 2.32.3 |
| git-scm | git | >= 2.33.2 < 2.33.4 | 2.33.4 |
| git-scm | git | >= 2.34.2 < 2.34.4 | 2.34.4 |
| git-scm | git | >= 2.35.2 < 2.35.4 | 2.35.4 |
| git-scm | git | >= 2.36.0 < 2.36.2 | 2.36.2 |
| git-scm | git | >= 2.37.0 < 2.37.1 | 2.37.1 |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian6.0MEDIUM
vendor_msrc6.0HIGH
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
Git vulnerabilities
vendor_ubuntu·2022-07-13·CVSS 6.0
CVE-2022-29187 [MEDIUM] Git vulnerabilities
Title: Git vulnerabilities
Summary: Git could be made to run arbitrary commands as an administrator
if it received specially crafted inputs.
Carlo Marcelo Arenas Belón discovered that an issue related to CVE-2022-24765
still affected Git. An attacker could possibly use this issue to
run arbitrary commands as administrator. (CVE-2022-29187)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
git: Bypass of safe.directory protections
vendor_redhat·2022-07-12·CVSS 6.0
CVE-2022-29187 [MEDIUM] CWE-283 git: Bypass of safe.directory protections
git: Bypass of safe.directory protections
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not poss
Apple
CVE-2022-24765: Xcode 13.4
vendor_apple·2022-05-16·CVSS 6.0
CVE-2022-24765 [MEDIUM] CVE-2022-24765: Xcode 13.4
Apple Security Update: About the security content of Xcode 13.4
Product: Xcode
Version: 13.4
CVE: CVE-2022-24765
Component: Git
Impact: On multi-user machines Git users might find themselves unexpectedly in a Git worktree
Description: A logic issue was addressed with improved state management.
Ubuntu
Git vulnerability
vendor_ubuntu·2022-04-25
CVE-2022-24765 Git vulnerability
Title: Git vulnerability
Summary: Git could be made to run arbitrary commands in platforms with multiple users
support.
USN-5376-1 fixed vulnerabilities in Git. This update provides the corresponding
updates for Ubuntu 22.04 LTS.
Original advisory details:
俞晨东 discovered that Git incorrectly handled certain repository paths
in platforms with multiple users support. An attacker could possibly use
this issue to run arbitrary commands.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
GitHub: Uncontrolled search for the Git directory in Git for Windows
vendor_msrc·2022-04-12·CVSS 6.0
CVE-2022-24765 [MEDIUM] GitHub: Uncontrolled search for the Git directory in Git for Windows
GitHub: Uncontrolled search for the Git directory in Git for Windows
FAQ: Why is this GitHub CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Git for Windows software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Visual Studio: Visual Studio
GitHub: GitHub
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: http://aka.ms/vs/15/
Red Hat
git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree
vendor_redhat·2022-04-12·CVSS 6.0
CVE-2022-24765 [MEDIUM] CWE-427 git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree
git: On multi-user machines Git users might find themselves unexpectedly in a Git worktree
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config spec
Debian
CVE-2022-29187: git - Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36...
vendor_debian·2022·CVSS 6.0
CVE-2022-29187 [MEDIUM] CVE-2022-29187: git - Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36...
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the e
Debian
CVE-2022-24765: git - Git for Windows is a fork of Git containing Windows-specific patches. This vulne...
vendor_debian·2022·CVSS 6.0
CVE-2022-24765 [MEDIUM] CVE-2022-24765: git - Git for Windows is a fork of Git containing Windows-specific patches. This vulne...
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by start
GHSA
gix-path improperly resolves configuration path reported by Git
ghsa·2024-09-06
CVE-2024-45405 [MEDIUM] CWE-41 gix-path improperly resolves configuration path reported by Git
gix-path improperly resolves configuration path reported by Git
### Summary
`gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution.
### Details
In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation.
Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths ([`650a1b5`](https://github.com/Byron/gitoxide/commit/650a1b5cf25e086197cc55a68525a411e1c28031)). Instead, t
OSV
gix-path improperly resolves configuration path reported by Git
osv·2024-09-06
CVE-2024-45405 gix-path improperly resolves configuration path reported by Git
gix-path improperly resolves configuration path reported by Git
### Summary
`gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution.
### Details
In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation.
Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths ([`650a1b5`](https://github.com/Byron/gitoxide/commit/650a1b5cf25e086197cc55a68525a411e1c28031)). Instead, t
OSV
gix-path improperly resolves configuration path reported by Git
osv·2024-09-06
CVE-2024-45405 [MEDIUM] gix-path improperly resolves configuration path reported by Git
gix-path improperly resolves configuration path reported by Git
### Summary
`gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing unusual or non-ASCII characters, in rare cases enabling a local attacker to inject configuration leading to code execution.
### Details
In `gix_path::env`, the underlying implementation of the `installation_config` and `installation_config_prefix` functions calls `git config -l --show-origin` to find the path of a file to treat as belonging to the `git` installation.
Affected versions of `gix-path` do not pass `-z`/`--null` to cause `git` to report literal paths ([`650a1b5`](https://github.com/Byron/gitoxide/commit/650a1b5cf25e086197cc55a68525a411e1c28031)). Instead, t
GHSA
gix-path can use a fake program files location
ghsa·2024-07-18
CVE-2024-40644 [HIGH] CWE-427 gix-path can use a fake program files location
gix-path can use a fake program files location
### Summary
When looking for Git for Windows so it can run it to report its paths, `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account.
### Details
Windows permits limited user accounts without administrative privileges to create new directories in the root of the system drive. While `gix-path` first looks for `git` using a `PATH` search, in version 0.10.8 it also has a fallback strategy on Windows of checking two hard-coded paths intended to be the 64-bit and 32-bit Program Files directories:
https://github.com/Byron/gitoxide/blob/6cd8b4665bb7582f744c3244abaef812be39ec35/gix-path/src/env/git.rs#L9-L14
Existing functions, as well as the newly introduced `exe_invocation` funct
OSV
gix-path can use a fake program files location
osv·2024-07-18
CVE-2024-40644 gix-path can use a fake program files location
gix-path can use a fake program files location
### Summary
When looking for Git for Windows so it can run it to report its paths, `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account.
### Details
Windows permits limited user accounts without administrative privileges to create new directories in the root of the system drive. While `gix-path` first looks for `git` using a `PATH` search, in version 0.10.8 it also has a fallback strategy on Windows of checking [two hard-coded paths](https://github.com/Byron/gitoxide/blob/6cd8b4665bb7582f744c3244abaef812be39ec35/gix-path/src/env/git.rs#L9-L14) intended to be the 64-bit and 32-bit Program Files directories:
```rust
/// Other places to find Git in.
#[cfg(windows)]
pub(super) stat
OSV
gix-path can use a fake program files location
osv·2024-07-18
CVE-2024-40644 [HIGH] gix-path can use a fake program files location
gix-path can use a fake program files location
### Summary
When looking for Git for Windows so it can run it to report its paths, `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account.
### Details
Windows permits limited user accounts without administrative privileges to create new directories in the root of the system drive. While `gix-path` first looks for `git` using a `PATH` search, in version 0.10.8 it also has a fallback strategy on Windows of checking two hard-coded paths intended to be the 64-bit and 32-bit Program Files directories:
https://github.com/Byron/gitoxide/blob/6cd8b4665bb7582f744c3244abaef812be39ec35/gix-path/src/env/git.rs#L9-L14
Existing functions, as well as the newly introduced `exe_invocation` funct
OSV
git vulnerabilities
osv·2022-07-13·CVSS 7.8
CVE-2022-24765 [HIGH] git vulnerabilities
git vulnerabilities
Carlo Marcelo Arenas Belón discovered that an issue related to CVE-2022-24765
still affected Git. An attacker could possibly use this issue to
run arbitrary commands as administrator. (CVE-2022-29187)
OSV
CVE-2022-29187: Git is a distributed revision control system
osv·2022-07-12·CVSS 7.8
CVE-2022-29187 [HIGH] CVE-2022-29187: Git is a distributed revision control system
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the e
OSV
CVE-2022-24765: Git for Windows is a fork of Git containing Windows-specific patches
osv·2022-04-12·CVSS 7.8
CVE-2022-24765 [HIGH] CVE-2022-24765: Git for Windows is a fork of Git containing Windows-specific patches
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by start
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/May/31http://www.openwall.com/lists/oss-security/2022/04/12/7https://git-scm.com/book/en/v2/Appendix-A%3A-Git-in-Other-Environments-Git-in-Bashhttps://git-scm.com/docs/git#Documentation/git.txt-codeGITCEILINGDIRECTORIEScodehttps://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2https://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PTN5NYEHYN2OQSHSAMCNICZNK2U4QH6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BENQYTDGUL6TF3UALY6GSIEXIHUIYNWM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDI325LOO2XBDDKLINOAQJEG6MHAURZE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIKWISWUDFT2FAITYIA6372BVLH3OOOC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVOLER2PIGMHPQMDGG4RDE2KZB74QLA2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SLP42KIZ6HACTVZMZLJLFJQ4W2XYT27M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZG5CDUQ27OWTPC5MQOR4UASNXHWEZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDZRZAL7QULOB6V7MKT66MOMWJLBJPX4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YROCMBWYFKRSS64PO6FUNM6L7LKBUKVW/https://security.gentoo.org/glsa/202312-15https://support.apple.com/kb/HT213261http://seclists.org/fulldisclosure/2022/May/31http://www.openwall.com/lists/oss-security/2022/04/12/7https://git-scm.com/book/en/v2/Appendix-A%3A-Git-in-Other-Environments-Git-in-Bashhttps://git-scm.com/docs/git#Documentation/git.txt-codeGITCEILINGDIRECTORIEScodehttps://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2https://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5PTN5NYEHYN2OQSHSAMCNICZNK2U4QH6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BENQYTDGUL6TF3UALY6GSIEXIHUIYNWM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDI325LOO2XBDDKLINOAQJEG6MHAURZE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIKWISWUDFT2FAITYIA6372BVLH3OOOC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVOLER2PIGMHPQMDGG4RDE2KZB74QLA2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SLP42KIZ6HACTVZMZLJLFJQ4W2XYT27M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZG5CDUQ27OWTPC5MQOR4UASNXHWEZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDZRZAL7QULOB6V7MKT66MOMWJLBJPX4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YROCMBWYFKRSS64PO6FUNM6L7LKBUKVW/https://security.gentoo.org/glsa/202312-15https://support.apple.com/kb/HT213261
2022-04-12
Published