Exposición de git

Development
34
score de exposición
60
sitios usan
1
en explotación
4
críticos
Análisis Vexday

O ecossistema do Git apresenta um volume relativamente contido de vulnerabilidades catalogadas (38 CVEs), mas a proporção de falhas em exploração ativa supera em 5,8 vezes a média geral do catálogo CISA KEV, o que indica risco desproporcional considerando o tamanho do conjunto. O tipo de falha mais recorrente é CWE-22 (Path Traversal), uma classe de vulnerabilidade frequentemente explorada para acesso não autorizado a arquivos e diretórios fora do escopo pretendido. O maior valor EPSS observado no conjunto chega a 0,886, sinalizando que ao menos uma CVE tem probabilidade muito elevada de exploração ativa estimada por modelos preditivos. A CVE mais perigosa monitorada atualmente é CVE-2025-48384, com EPSS de 0,028, que deve ser avaliada em conjunto com as 4 falhas de severidade crítica presentes no catálogo ao se priorizar ciclos de atualização e revisão de configuração.

CVEs

38 resultados
CVE-2024-32021LOWLocal Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directoryEPSS 1.0%CVE-2023-25815LOWGit looks for localized messages in the wrong placeEPSS 1.0%CVE-2025-48385HIGHGit alllows arbitrary file writes via bundle-uri parameter injectionEPSS 0.9%CVE-2022-24765MEDIUMUncontrolled search for the Git directory in Git for WindowsEPSS 0.8%CVE-2023-22490MEDIUMGit vulnerable to local clone-based data exfiltration with non-local transportsEPSS 0.7%CVE-2024-50349LOWGit does not sanitize URLs when asking for credentials interactivelyEPSS 0.7%CVE-2024-32020LOWCloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at willEPSS 0.5%CVE-2024-52005HIGHThe sideband payload is passed unfiltered to the terminal in gitEPSS 0.5%CVE-2022-29187HIGHBypass of safe.directory protections in GitEPSS 0.4%CVE-2019-1348An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The EPSS 0.4%CVE-2022-31012HIGHGit for Windows' installer can be tricked into executing an untrusted binaryEPSS 0.4%CVE-2023-23618HIGHgitk can inadvertently call executables in the worktreeEPSS 0.4%CVE-2023-29011HIGHGit for Windows's config file of `connect.exe` is susceptible to malicious placingEPSS 0.4%CVE-2023-29012HIGHGit CMD erroneously executes `doskey.exe` in the current directory, if it existsEPSS 0.4%CVE-2023-22743HIGHGit for Windows' installer is susceptible to DLL side loading attacksEPSS 0.4%CVE-2025-48386MEDIUMGit allows a buffer overflow in 'wincred' credential helperEPSS 0.3%CVE-2026-32631HIGHGit for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary serversEPSS 0.3%CVE-2025-66413HIGHGit for Windows leaks NTLM hash when cloning from an attacker-controlled serverEPSS 0.3%