Friday, June 26, 2026

Vulnerability: Git provides patches for Windows and multi-user systems

Date:

Vulnerability reported by the GitHub version control platform on April 12, 2022 in the NIST National Vulnerability Database CVE-2022-24765 describes a potential vulnerability in local Git installations, which may particularly affect Git for Windows and multi-user systems. GitHub itself and its users are not directly affected by this, but the platform still recommends a quick update to the v2.35.2 maintenance release provided by Git.

As the CVE description shows, attackers on multi-user systems could create a .git directory at a shared level above the main working directory. On Windows, this opens the possibility of creating C:\.git\config, for example, so that all Git calls made outside of a repository read the values ​​configured there. Because some configuration variables like core.fsmonitor Git can cause arbitrary commands to be executed, attackers could inject their own commands into the system and trigger them. Git v2.35.2 does not allow switching to a top level git directory when accompanied by a user switch. The necessary deviations from this new behavior can be found in the also new safe.directory-Set configuration.

another in CVE-2022-24767 The described vulnerability that allows the placement of potentially malicious .dll files affects the Git Uninstaller for Windows. If the uninstaller of a system-Account running in the user’s temporary directory as usual, any authenticated user could inject .dll files into the process, since the default permissions of system allow this for C:\Windows\Temp. Git for Windows v2.35.2 close this gap.

More details about the vulnerabilities can be found in the GitHub Blog as well as in the Git Project Announcement of Maintenance Release v2.35.2which was released at the same time as other patches v2.30.3, v2.31.2, v2.32.1, v2.33.2 and v2.34.2.


(Map)

to the home page

Toni Morrison
Toni Morrison
Toni Morrison was a celebrated American author whose novels earned worldwide recognition for their depth, artistry, and cultural significance. Her influential works continue to inspire readers and writers across generations.

Share post:

Popular

More like this
Related

Fellowship Season 3 Launches With New Hero, Dungeons, and Major Gameplay Overhaul

Rise of the Heskyr Brings the Biggest Update Yet...

Black Desert Marks Four Years of Self-Publishing With Global Community Event

New “Desert Light” Event Encourages Players Worldwide to Work...

The Grinch Returns in New 3D Adventure With Humor, Action, and Holiday Spirit

The Grinch 2: Saving Christmas Set for September 2026...

Leadership and Management at Soft2Bet: How Direction Shapes Growth

Running an international technology company like Soft2Bet is, before...