[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-29187Date: (C)2022-07-15   (M)2024-01-22


Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score : 6.9
Exploit Score: 1.8Exploit Score: 3.4
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
http://seclists.org/fulldisclosure/2022/Nov/1
FEDORA-2022-2a5de7cb8b
FEDORA-2022-dfd7e7fc0e
FEDORA-2023-1068309389
FEDORA-2023-3ec32f6d4e
FEDORA-2023-470c7ea49e
FEDORA-2023-e3c8abd37e
GLSA-202312-15
GLSA-202401-17
https://lists.debian.org/debian-lts-announce/2022/12/msg00025.html
http://www.openwall.com/lists/oss-security/2022/07/14/1
https://github.blog/2022-04-12-git-security-vulnerability-announced
https://github.com/git/git/security/advisories/GHSA-j342-m5hw-rr3v
https://lore.kernel.org/git/xmqqv8s2fefi.fsf%40gitster.g/T/#u
https://support.apple.com/kb/HT213496

CWE    1
CWE-427
OVAL    43
oval:org.secpod.oval:def:1601574
oval:org.secpod.oval:def:89333
oval:org.secpod.oval:def:3301239
oval:org.secpod.oval:def:86481
...

© SecPod Technologies