CVE-2022-29187
- EPSS 0.05%
- Veröffentlicht 12.07.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:40
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue ...
CVE-2022-24765
- EPSS 0.17%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:02
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C...
CVE-2022-24975
- EPSS 0.67%
- Veröffentlicht 11.02.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:29
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --...
CVE-2021-40330
- EPSS 0.38%
- Veröffentlicht 31.08.2021 04:15:10
- Zuletzt bearbeitet 21.11.2024 06:23:52
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.
CVE-2021-21300
- EPSS 74.69%
- Veröffentlicht 09.03.2021 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:47:58
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be e...
CVE-2020-11008
- EPSS 1.52%
- Veröffentlicht 21.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:56:34
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open fo...
CVE-2020-5260
- EPSS 32.57%
- Veröffentlicht 14.04.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 05:33:47
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from se...
CVE-2014-9390
- EPSS 53.35%
- Veröffentlicht 12.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 02:20:45
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all ve...
CVE-2019-1353
- EPSS 0.18%
- Veröffentlicht 24.01.2020 22:15:19
- Zuletzt bearbeitet 21.11.2024 04:36:32
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a...
CVE-2019-1348
- EPSS 0.04%
- Veröffentlicht 24.01.2020 22:15:19
- Zuletzt bearbeitet 21.11.2024 04:36:31
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... an...