PT-2023-5862 · Git · Git For Windows

·

CVE-2023-29012

·

Publicado

2022-11-08

·

Atualizado

2023-05-04

CVSS v3.1

7.2

Alta

VetorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Git for Windows versions prior to 2.40.1
Description The issue is related to an Uncontrolled Search Path Element vulnerability. It affects users of Git CMD who start the command in an untrusted directory, allowing maliciously-placed doskey.exe to be executed silently. This could potentially enable an attacker to execute arbitrary code.
Recommendations For versions prior to 2.40.1, update to Git for Windows version 2.40.1 to resolve the issue. As a temporary workaround, avoid using Git CMD or, if using Git CMD, avoid starting it in an untrusted directory.

Exploit

Correção

DoS

Uncontrolled Search Path Element

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06554
BDU:2023-06555
BDU:2023-06647
CVE-2023-29012
GHSA-GQ5X-V87V-8F7G

Produtos afetados

Git For Windows