Exposure of git

Development
34
exposure score
60
sites use
1
exploited
4
critical
Vexday analysis

O ecossistema do Git apresenta um volume relativamente contido de vulnerabilidades catalogadas (38 CVEs), mas a proporção de falhas em exploração ativa supera em 5,8 vezes a média geral do catálogo CISA KEV, o que indica risco desproporcional considerando o tamanho do conjunto. O tipo de falha mais recorrente é CWE-22 (Path Traversal), uma classe de vulnerabilidade frequentemente explorada para acesso não autorizado a arquivos e diretórios fora do escopo pretendido. O maior valor EPSS observado no conjunto chega a 0,886, sinalizando que ao menos uma CVE tem probabilidade muito elevada de exploração ativa estimada por modelos preditivos. A CVE mais perigosa monitorada atualmente é CVE-2025-48384, com EPSS de 0,028, que deve ser avaliada em conjunto com as 4 falhas de severidade crítica presentes no catálogo ao se priorizar ciclos de atualização e revisão de configuração.

CVEs

38 results
CVE-2025-48384HIGHGit allows arbitrary code execution through broken config quotingEPSS 2.8%KEVCVE-2021-21300HIGHmalicious repositories can execute remote code while cloningEPSS 88.6%CVE-2022-23521CRITICALgitattributes parsing integer overflow in gitEPSS 56.3%CVE-2023-25652HIGH"git apply --reject" partially-controlled arbitrary file writeEPSS 51.9%CVE-2022-41903CRITICALInteger overflow in `git archive`, `git log --format` leading to RCE in gitEPSS 44.3%CVE-2024-32002CRITICALGit's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code ExecutionEPSS 29.2%CVE-2020-5260CRITICALmalicious URLs may cause Git to present stored credentials to the wrong serverEPSS 10.0%CVE-2022-41953HIGHGit clone remote code execution vulnerability in git-for-windowsEPSS 6.8%CVE-2023-29007HIGHArbitrary configuration injection via `git submodule deinit`EPSS 6.1%CVE-2022-25648HIGHCommand InjectionEPSS 4.9%CVE-2019-1387An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. RecuEPSS 4.4%CVE-2020-11008MEDIUMMalicious URLs can still cause Git to send a stored credential to the wrong serverEPSS 3.9%CVE-2022-39260HIGHGit vulnerable to Remote Code Execution via Heap overflow in `git shell`EPSS 3.1%CVE-2021-23632MEDIUMRemote Code Execution (RCE)EPSS 2.4%CVE-2019-1353An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. WhenEPSS 2.2%CVE-2024-32004HIGHGit vulnerable to Remote Code Execution while cloning special-crafted local repositoriesEPSS 1.4%CVE-2022-39253MEDIUMGit subject to exposure of sensitive information via local clone of symbolic linksEPSS 1.3%CVE-2023-23946MEDIUMGit's `git apply` overwriting paths outside the working treeEPSS 1.1%CVE-2024-52006LOWNewline confusion in credential helpers can lead to credential exfiltration in gitEPSS 1.0%CVE-2024-32465HIGHGit's protections for cloning untrusted repositories can be bypassedEPSS 1.0%