Описание
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to git apply, a path outside the working tree can be overwritten as the user who is running git apply. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use git apply --stat to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1:2.17.1-1ubuntu0.16 |
| devel | released | 1:2.39.2-1ubuntu1 |
| esm-infra/bionic | released | 1:2.17.1-1ubuntu0.16 |
| esm-infra/focal | released | 1:2.25.1-1ubuntu3.10 |
| esm-infra/xenial | released | 1:2.7.4-0ubuntu1.10+esm5 |
| focal | released | 1:2.25.1-1ubuntu3.10 |
| jammy | released | 1:2.34.1-1ubuntu1.8 |
| kinetic | released | 1:2.37.2-1ubuntu1.4 |
| lunar | released | 1:2.39.2-1ubuntu1 |
| trusty | ignored | end of standard support |
Показывать по
EPSS
6.2 Medium
CVSS3
Связанные уязвимости
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
GitHub: CVE-2023-23946 mingit Remote Code Execution Vulnerability
Git, a revision control system, is vulnerable to path traversal prior ...
Уязвимость распределенной системы управления версиями Git, связанная с неправильным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы в системе
EPSS
6.2 Medium
CVSS3