Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24826

Опубликовано: 20 апр. 2022
Источник: nvd
CVSS3: 9.8
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

On Windows, if Git LFS operates on a malicious repository with a ..exe file as well as a file named git.exe, and git.exe is not found in PATH, the ..exe program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems. Similarly, if the malicious repository contains files named ..exe and cygpath.exe, and cygpath.exe is not found in PATH, the ..exe program will be executed when certain Git LFS commands are run. More generally, if the current working directory contains any file with a base name of . and a file extension from PATHEXT (except .bat and .cmd), and also contains another file with the same base name as a program Git LFS intends to execute (such as git, cygpath, or uname) and any file extension from PATHEXT (including .bat and .cmd), then, on Windows, when Git LFS attempts to execute the intended program the ..exe, ..com, etc., file will be executed instead, but only if the intended progra

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:git_large_file_storage_project:git_large_file_storage:*:*:*:*:*:*:*:*
Версия от 2.12.1 (включая) до 3.1.3 (исключая)

EPSS

Процентиль: 50%
0.00264
Низкий

9.8 Critical

CVSS3

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426
CWE-426

Связанные уязвимости

CVSS3: 9.8
github
почти 4 года назад

Git LFS can execute a binary from the current directory on Windows

EPSS

Процентиль: 50%
0.00264
Низкий

9.8 Critical

CVSS3

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-426
CWE-426