Git For Windows Project Git For Windows vulnerabilities

7 known vulnerabilities affecting git_for_windows_project/git_for_windows.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-29011HIGHCVSS 7.5fixed in 2.40.12023-04-25
CVE-2023-29011 [HIGH] CWE-427 CVE-2023-29011: Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which imple Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. The location of `connect.exe`'s config file is hard-coded as `/etc/connectrc` which will typically be interpreted a
nvd
CVE-2023-29012HIGHCVSS 7.2fixed in 2.40.12023-04-25
CVE-2023-29012 [HIGH] CWE-427 CVE-2023-29012: Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted by an Uncontrolles Search Path Element vulnerability. Maliciously-placed `doskey.exe` would be executed silently upon running Git CMD. The problem has been patched in Git for Windows v2.40.1. As a workaro
nvd
CVE-2023-25815LOWCVSS 3.3fixed in 2.40.12023-04-25
CVE-2023-25815 [LOW] CWE-22 CVE-2023-25815: In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. A In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's implicit initialization no longer uses the runtime prefix but uses the hard-code
nvd
CVE-2023-22743HIGHCVSS 7.2fixed in 2.39.22023-02-14
CVE-2023-22743 [HIGH] CWE-426 CVE-2023-22743: Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows ver Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users with local write access to place mal
nvd
CVE-2023-23618HIGHCVSS 8.6fixed in 2.39.22023-02-14
CVE-2023-23618 [HIGH] CWE-426 CVE-2023-23618: Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows ver Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. A patch is available in version 2.39.2.
nvd
CVE-2022-24767HIGHCVSS 7.8fixed in 2.35.22022-04-12
CVE-2022-24767 [HIGH] CWE-427 CVE-2022-24767: GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user acco GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
nvd
CVE-2016-9274HIGHCVSS 7.8≥ 1.0.0, ≤ 1.9.42016-11-11
CVE-2016-9274 [HIGH] CWE-426 CVE-2016-9274: Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
nvd
Git For Windows Project Git For Windows vulnerabilities | cvebase