CVE-2022-29187 (CNNVD-202207-1179)
中文标题:
Github Git 代码问题漏洞
英文标题:
Bypass of safe.directory protections in Git
漏洞描述
中文描述:
Github Git是一套免费、开源的分布式版本控制系统。 Github Git 存在安全漏洞,该漏洞源于可以绕过安全目录保护,以下产品和版本受到影响:Git 2.37.1、2.36.2、2.35.4、2.34.4、2.33.4、2.32.3、2.31.4 和 2.30.5 之前版本。
英文描述:
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| git | git | >= 2.30.3, < 2.30.5 | - | - |
cpe:2.3:a:git:git:>=_2.30.3,_<_2.30.5:*:*:*:*:*:*:*
|
| git | git | >= 2.31.2, < 2.31.4 | - | - |
cpe:2.3:a:git:git:>=_2.31.2,_<_2.31.4:*:*:*:*:*:*:*
|
| git | git | >= 2.32.1, < 2.32.3 | - | - |
cpe:2.3:a:git:git:>=_2.32.1,_<_2.32.3:*:*:*:*:*:*:*
|
| git | git | >= 2.33.2, < 2.33.4 | - | - |
cpe:2.3:a:git:git:>=_2.33.2,_<_2.33.4:*:*:*:*:*:*:*
|
| git | git | >= 2.34.2, < 2.34.4 | - | - |
cpe:2.3:a:git:git:>=_2.34.2,_<_2.34.4:*:*:*:*:*:*:*
|
| git | git | >= 2.35.2, < 2.35.4 | - | - |
cpe:2.3:a:git:git:>=_2.35.2,_<_2.35.4:*:*:*:*:*:*:*
|
| git | git | >= 2.36, < 2.36.2 | - | - |
cpe:2.3:a:git:git:>=_2.36,_<_2.36.2:*:*:*:*:*:*:*
|
| git | git | >= 2.37, < 2.37.1 | - | - |
cpe:2.3:a:git:git:>=_2.37,_<_2.37.1:*:*:*:*:*:*:*
|
| git-scm | git | * | - | - |
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 35 | - | - |
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 36 | - | - |
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 37 | - | - |
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
|
| apple | xcode | * | - | - |
cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*
|
| debian | debian_linux | 10.0 | - | - |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2022-29187 |
2025-11-11 15:21:23 | 2025-11-11 07:37:29 |
| NVD | nvd_CVE-2022-29187 |
2025-11-11 14:58:21 | 2025-11-11 07:45:44 |
| CNNVD | cnnvd_CNNVD-202207-1179 |
2025-11-11 15:10:56 | 2025-11-11 07:57:22 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202207-1179
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 8 -> 14
- data_sources: ['cve'] -> ['cve', 'nvd']