Git's `git apply` overwriting paths outside the working tree
Published Feb 14, 2023
7.5
HIGHCVSS 3.1
EPSS 1.14%
Description
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
Affected products
-
- Version < 2.30.8StatusaffectedConstraints-
- Version >= 2.31.0, < 2.31.7StatusaffectedConstraints-
- Version >= 2.32.0, < 2.32.6StatusaffectedConstraints-
- Version >= 2.33.0, < 2.33.7StatusaffectedConstraints-
- Version >= 2.34.0, < 2.34.7StatusaffectedConstraints-
- Version >= 2.35.0, < 2.35.7StatusaffectedConstraints-
- Version >= 2.36.0, < 2.36.5StatusaffectedConstraints-
- Version >= 2.37.0, < 2.37.6StatusaffectedConstraints-
- Version >= 2.38.0, < 2.38.4StatusaffectedConstraints-
- Version >= 2.39.0, < 2.39.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Git | Git | n/a |
|
- < 2.30.8
- ≥ 2.31.0 · < 2.31.7
- ≥ 2.32.0 · < 2.32.6
- ≥ 2.33.0 · < 2.33.7
- ≥ 2.34.0 · < 2.34.7
- ≥ 2.35.0 · < 2.35.7
- ≥ 2.36.0 · < 2.36.5
- ≥ 2.37.0 · < 2.37.6
- ≥ 2.38.0 · < 2.38.4
- ≥ 2.39.0 · < 2.39.2
No data.
Red Hat Enterprise Linux 8
git-0:2.39.3-1.el8_8
Fixed · RHSA-2023:3246
Red Hat Enterprise Linux 8.6 Extended Update Support
git-0:2.31.8-1.el8_6
Fixed · RHSA-2024:0407
Red Hat Enterprise Linux 9
git-0:2.39.3-1.el9_2
Fixed · RHSA-2023:3245
Red Hat Enterprise Linux 6
git
Out of support scope
Red Hat Enterprise Linux 7
git
Out of support scope
Red Hat JBoss Data Grid 7
git
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | git-0:2.39.3-1.el8_8 | Fixed | RHSA-2023:3246 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | git-0:2.31.8-1.el8_6 | Fixed | RHSA-2024:0407 |
| Red Hat Enterprise Linux 9 | git-0:2.39.3-1.el9_2 | Fixed | RHSA-2023:3245 |
| Red Hat Enterprise Linux 6 | git | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | git | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | git | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability marked as Moderate severity and it's less likely to be exploitable because it requires a specially crafted malicious patch to be applied via git apply, to overwrite files outside the working tree of the user running git apply. This could lead to some compromise of integrity of resources under certain circumstances, however it does not compromise the whole system or gain additional privileges to execute arbitrary code, or allow remote users to cause a denial of service.
Red Hat mitigation
Use git apply --stat to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-23946 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2168161 Issue Tracking
- https://github.blog/2023-02-14-git-security-vulnerabilities-announced-3/
- https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd x_refsource_MISCPatch
- https://github.com/git/git/security/advisories/GHSA-r87m-v37r-cwfh x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-23946
- https://security.gentoo.org/glsa/202312-15
- https://www.cve.org/CVERecord?id=CVE-2023-23946
Change history (0)
No recorded changes yet.