Логотип exploitDog
bind:CVE-2022-24765
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24765

Количество 15

Количество 15

ubuntu логотип

CVE-2022-24765

около 3 лет назад

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access ...

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2022-24765

около 3 лет назад

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access ...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-24765

около 3 лет назад

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access fro

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2022-24765

около 3 лет назад

GitHub: Uncontrolled search for the Git directory in Git for Windows

EPSS: Низкий
debian логотип

CVE-2022-24765

около 3 лет назад

Git for Windows is a fork of Git containing Windows-specific patches. ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1484-1

около 3 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1306-1

около 3 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1260-1

около 3 лет назад

Security update for git

EPSS: Низкий
fstec логотип

BDU:2022-02723

около 3 лет назад

Уязвимость распределенной системы управления версиями Git, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии или выполнить произвольные команды

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3494-1

больше 2 лет назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3283-1

почти 3 года назад

Security update for libgit2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3495-1

больше 2 лет назад

Security update for libgit2

EPSS: Низкий
redos логотип

ROS-20220516-05

около 3 лет назад

Множественные уязвимости Git

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2859

около 2 лет назад

ELSA-2023-2859: git security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2319

около 2 лет назад

ELSA-2023-2319: git security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access ...

CVSS3: 6
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access ...

CVSS3: 7.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git directory. Git would then respect any config in said Git directory. Git Bash users who set `GIT_PS1_SHOWDIRTYSTATE` are vulnerable as well. Users who installed posh-gitare vulnerable simply by starting a PowerShell. Users of IDEs such as Visual Studio are vulnerable: simply creating a new project would already read and respect the config specified in `C:\.git\config`. Users of the Microsoft fork of Git are vulnerable simply by starting a Git Bash. The problem has been patched in Git for Windows v2.35.2. Users unable to upgrade may create the folder `.git` on all drives where Git commands are run, and remove read/write access fro

CVSS3: 6
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2022-24765

GitHub: Uncontrolled search for the Git directory in Git for Windows

0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-24765

Git for Windows is a fork of Git containing Windows-specific patches. ...

CVSS3: 6
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1484-1

Security update for git

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1306-1

Security update for git

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1260-1

Security update for git

0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-02723

Уязвимость распределенной системы управления версиями Git, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии или выполнить произвольные команды

CVSS3: 6
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3494-1

Security update for libgit2

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3283-1

Security update for libgit2

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3495-1

Security update for libgit2

больше 2 лет назад
redos логотип
ROS-20220516-05

Множественные уязвимости Git

около 3 лет назад
oracle-oval логотип
ELSA-2023-2859

ELSA-2023-2859: git security and bug fix update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-2319

ELSA-2023-2319: git security and bug fix update (MODERATE)

около 2 лет назад

Уязвимостей на страницу