Vulnerabilidades em git-for-windows
10 resultadosAnálise Vexday
Git for Windows apresenta 10 vulnerabilidades catalogadas, nenhuma em exploração ativa conhecida e nenhuma crítica (CVSS ≥9.0). A fraqueza predominante é CWE-426 (confiança em componentes de fonte não confiável), indicando riscos potenciais na cadeia de suprimentos; porém, a ausência de divulgações recentes (últimos 90 dias) sugere que o risco atual não está em escalação.
CVE-2022-41953HIGHGit clone remote code execution vulnerability in git-for-windowsEPSS 6.8%CVE-2023-25815LOWGit looks for localized messages in the wrong placeEPSS 1.0%CVE-2022-24765MEDIUMUncontrolled search for the Git directory in Git for WindowsEPSS 0.8%CVE-2022-31012HIGHGit for Windows' installer can be tricked into executing an untrusted binaryEPSS 0.4%CVE-2023-23618HIGHgitk can inadvertently call executables in the worktreeEPSS 0.4%CVE-2023-29011HIGHGit for Windows's config file of `connect.exe` is susceptible to malicious placingEPSS 0.4%CVE-2023-29012HIGHGit CMD erroneously executes `doskey.exe` in the current directory, if it existsEPSS 0.4%CVE-2023-22743HIGHGit for Windows' installer is susceptible to DLL side loading attacksEPSS 0.4%CVE-2026-32631HIGHGit for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary serversEPSS 0.3%CVE-2025-66413HIGHGit for Windows leaks NTLM hash when cloning from an attacker-controlled serverEPSS 0.3%