CVE-2022-29187
published 2022-07-12CVE-2022-29187: Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
36.1th percentile
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 14.1 | 14.1 |
| apple | xcode | — | — |
| debian | debian_linux | — | — |
| debian | git | < git 1:2.37.2-1 (bookworm) | git 1:2.37.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| git-scm | git | >= 2.30.3 < 2.30.5 | 2.30.5 |
| git-scm | git | >= 2.31.2 < 2.31.4 | 2.31.4 |
| git-scm | git | >= 2.32.1 < 2.32.3 | 2.32.3 |
| git-scm | git | >= 2.33.2 < 2.33.4 | 2.33.4 |
| git-scm | git | >= 2.34.2 < 2.34.4 | 2.34.4 |
| git-scm | git | >= 2.35.2 < 2.35.4 | 2.35.4 |
| git-scm | git | >= 2.36.0 < 2.36.2 | 2.36.2 |
| git-scm | git | >= 2.37.0 < 2.37.1 | 2.37.1 |
| git | git | >= 0 < 1:2.30.2-1+deb11u1 | 1:2.30.2-1+deb11u1 |
| git | git | >= 0 < 1:2.37.2-1 | 1:2.37.2-1 |
| git | git | >= 0 < 1:2.37.2-1 | 1:2.37.2-1 |
| git | git | >= 0 < 1:2.37.2-1 | 1:2.37.2-1 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.12 | 1:2.17.1-1ubuntu0.12 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.5 | 1:2.25.1-1ubuntu3.5 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.4 | 1:2.34.1-1ubuntu1.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Apple
CVE-2022-29187: Xcode 14.1
vendor_apple·2022-11-01·CVSS 7.8
CVE-2022-29187 [HIGH] CVE-2022-29187: Xcode 14.1
Apple Security Update: About the security content of Xcode 14.1
Product: Xcode
Version: 14.1
CVE: CVE-2022-29187
Component: Git
Impact: Multiple issues in git
Description: Multiple issues were addressed by updating to git version 2.32.3.
Ubuntu
Git vulnerabilities
vendor_ubuntu·2022-07-13·CVSS 6.0
CVE-2022-29187 [MEDIUM] Git vulnerabilities
Title: Git vulnerabilities
Summary: Git could be made to run arbitrary commands as an administrator
if it received specially crafted inputs.
Carlo Marcelo Arenas Belón discovered that an issue related to CVE-2022-24765
still affected Git. An attacker could possibly use this issue to
run arbitrary commands as administrator. (CVE-2022-29187)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
git: Bypass of safe.directory protections
vendor_redhat·2022-07-12·CVSS 6.0
CVE-2022-29187 [MEDIUM] CWE-283 git: Bypass of safe.directory protections
git: Bypass of safe.directory protections
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not poss
Debian
CVE-2022-29187: git - Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36...
vendor_debian·2022·CVSS 6.0
CVE-2022-29187 [MEDIUM] CVE-2022-29187: git - Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36...
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the e
OSV
git vulnerabilities
osv·2022-07-13·CVSS 7.8
CVE-2022-24765 [HIGH] git vulnerabilities
git vulnerabilities
Carlo Marcelo Arenas Belón discovered that an issue related to CVE-2022-24765
still affected Git. An attacker could possibly use this issue to
run arbitrary commands as administrator. (CVE-2022-29187)
OSV
CVE-2022-29187: Git is a distributed revision control system
osv·2022-07-12·CVSS 7.8
CVE-2022-29187 [HIGH] CVE-2022-29187: Git is a distributed revision control system
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the e
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/Nov/1http://www.openwall.com/lists/oss-security/2022/07/14/1https://github.blog/2022-04-12-git-security-vulnerability-announcedhttps://github.com/git/git/security/advisories/GHSA-j342-m5hw-rr3vhttps://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDI325LOO2XBDDKLINOAQJEG6MHAURZE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIKWISWUDFT2FAITYIA6372BVLH3OOOC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVOLER2PIGMHPQMDGG4RDE2KZB74QLA2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZG5CDUQ27OWTPC5MQOR4UASNXHWEZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDZRZAL7QULOB6V7MKT66MOMWJLBJPX4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YROCMBWYFKRSS64PO6FUNM6L7LKBUKVW/https://lore.kernel.org/git/xmqqv8s2fefi.fsf%40gitster.g/T/#uhttps://security.gentoo.org/glsa/202312-15https://security.gentoo.org/glsa/202401-17https://support.apple.com/kb/HT213496http://seclists.org/fulldisclosure/2022/Nov/1http://www.openwall.com/lists/oss-security/2022/07/14/1https://github.blog/2022-04-12-git-security-vulnerability-announcedhttps://github.com/git/git/security/advisories/GHSA-j342-m5hw-rr3vhttps://lists.debian.org/debian-lts-announce/2022/12/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDI325LOO2XBDDKLINOAQJEG6MHAURZE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DIKWISWUDFT2FAITYIA6372BVLH3OOOC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVOLER2PIGMHPQMDGG4RDE2KZB74QLA2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRZG5CDUQ27OWTPC5MQOR4UASNXHWEZS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDZRZAL7QULOB6V7MKT66MOMWJLBJPX4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YROCMBWYFKRSS64PO6FUNM6L7LKBUKVW/https://lore.kernel.org/git/xmqqv8s2fefi.fsf%40gitster.g/T/#uhttps://security.gentoo.org/glsa/202312-15https://security.gentoo.org/glsa/202401-17https://support.apple.com/kb/HT213496
2022-07-12
Published