You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into C:\mingw64\bin\git.exe by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the C:\mingw64 folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in C:\.
See doc/triage.md for instructions on how to triage this report.
packages:
- module: github.com/git-for-windows/git
package: git
description: |
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mingw64\bin\git.exe` by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create the `C:\mingw64` folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders in `C:\`.
cves:
- CVE-2022-31012
links:
context:
- https://github.com/git-for-windows/git/releases/tag/v2.37.1.windows.1
- https://github.com/git-for-windows/git/security/advisories/GHSA-gjrj-fxvp-hjj2
The text was updated successfully, but these errors were encountered:
CVE-2022-31012 references github.com/git-for-windows/git, which may be a Go module.
Description:
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into
C:\mingw64\bin\git.exe
by mistake. This only happens upon a fresh install, not when upgrading Git for Windows. A patch is included in version 2.37.1. Two workarounds are available. Create theC:\mingw64
folder and remove read/write access from this folder, or disallow arbitrary authenticated users to create folders inC:\
.Links:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: