GitHub:CVE-2023-22490 使用非本地传输的基于本地克隆的数据泄露
CVE编号
CVE-2023-22490利用情况
暂无补丁情况
N/A披露时间
2023-02-15漏洞描述
Git 存在信息泄露漏洞。即使在使用非本地传输时,使用特制的存储库,Git 也可以被诱骗使用其本地克隆优化。尽管 Git 会中止源目录包含符号链接的本地克隆$GIT_DIR/objects,但objects目录本身可能仍然是符号链接。解决建议
安装 Windows 最新安全补丁。受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | git-scm | git | * | Up to (excluding) 2.30.8 | |||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.31.0 | Up to (excluding) 2.31.7 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.32.0 | Up to (excluding) 2.32.6 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.33.0 | Up to (excluding) 2.33.7 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.34.0 | Up to (excluding) 2.34.7 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.35.0 | Up to (excluding) 2.35.7 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.36.0 | Up to (excluding) 2.36.5 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.37.0 | Up to (excluding) 2.37.6 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.38.0 | Up to (excluding) 2.38.4 | ||||
运行在以下环境 | |||||||||
应用 | git-scm | git | * | From (including) 2.39.0 | Up to (excluding) 2.39.2 | ||||
运行在以下环境 | |||||||||
系统 | alpine_3.14 | git | * | Up to (excluding) 2.32.6-r0 | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.15 | git | * | Up to (excluding) 2.34.7-r0 | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.16 | git | * | Up to (excluding) 2.36.5-r0 | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.17 | git | * | Up to (excluding) 2.38.4-r0 | |||||
运行在以下环境 | |||||||||
系统 | alpine_3.18 | git | * | Up to (excluding) 2.39.2-r0 | |||||
运行在以下环境 | |||||||||
系统 | alpine_edge | git | * | Up to (excluding) 2.39.2-r0 | |||||
运行在以下环境 | |||||||||
系统 | amazon_2 | git | * | Up to (excluding) 2.39.2-1.amzn2.0.1 | |||||
运行在以下环境 | |||||||||
系统 | amazon_2023 | git | * | Up to (excluding) 2.39.2-1.amzn2023.0.1 | |||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | git | * | Up to (excluding) 2.38.4-1.80.amzn1 | |||||
运行在以下环境 | |||||||||
系统 | anolis_os_8 | gitk | * | Up to (excluding) 2.39.3-1.0.1 | |||||
运行在以下环境 | |||||||||
系统 | centos_8 | git-gui | * | Up to (excluding) 2.39.3-1.el8_8 | |||||
运行在以下环境 | |||||||||
系统 | debian_10 | git | * | Up to (excluding) 1:2.20.1-2+deb10u8 | |||||
运行在以下环境 | |||||||||
系统 | debian_11 | git | * | Up to (excluding) 1:2.30.2-1+deb11u2 | |||||
运行在以下环境 | |||||||||
系统 | debian_12 | git | * | Up to (excluding) 1:2.39.2-1 | |||||
运行在以下环境 | |||||||||
系统 | debian_sid | git | * | Up to (excluding) 1:2.39.2-1 | |||||
运行在以下环境 | |||||||||
系统 | fedora_36 | perl-Git | * | Up to (excluding) 2.39.2-1.fc36 | |||||
运行在以下环境 | |||||||||
系统 | fedora_37 | perl-Git | * | Up to (excluding) 2.39.2-1.fc37 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_aarch64_V10 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_aarch64_V10SP1 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_aarch64_V10SP2 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_aarch64_V10SP3 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_loongarch64_V10SP1 | git | * | Up to (excluding) 2.27.0-12.a.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_x86_64_V10 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_x86_64_V10SP1 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_x86_64_V10SP2 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | kylinos_x86_64_V10SP3 | git | * | Up to (excluding) 2.27.0-12.ky10 | |||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.4 | git | * | Up to (excluding) 2.35.3-150300.10.24.1 | |||||
运行在以下环境 | |||||||||
系统 | oracle_8 | oraclelinux-release | * | Up to (excluding) 2.39.3-1.el8_8 | |||||
运行在以下环境 | |||||||||
系统 | oracle_9 | oraclelinux-release | * | Up to (excluding) 2.39.3-1.el9_2 | |||||
运行在以下环境 | |||||||||
系统 | redhat_8 | git-gui | * | Up to (excluding) 2.39.3-1.el8_8 | |||||
运行在以下环境 | |||||||||
系统 | redhat_9 | git-daemon | * | Up to (excluding) 2.39.3-1.el9_2 | |||||
运行在以下环境 | |||||||||
系统 | suse_12_SP5 | git-core | * | Up to (excluding) 2.26.2-27.66.1 | |||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04 | git | * | Up to (excluding) 1:2.17.1-1ubuntu0.16 | |||||
运行在以下环境 | |||||||||
系统 | ubuntu_20.04 | git | * | Up to (excluding) 1:2.25.1-1ubuntu3.10 | |||||
运行在以下环境 | |||||||||
系统 | ubuntu_22.04 | git | * | Up to (excluding) 1:2.34.1-1ubuntu1.8 | |||||
运行在以下环境 | |||||||||
系统 | ubuntu_22.10 | git | * | Up to (excluding) 1:2.37.2-1ubuntu1.4 | |||||
运行在以下环境 | |||||||||
系统 | unionos_a | git | * | Up to (excluding) git-2.39.3-1.uelc20.01 | |||||
运行在以下环境 | |||||||||
系统 | unionos_e | git | * | Up to (excluding) git-2.27.0-15.uel20 | |||||
- 攻击路径 本地
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 需要
- 可用性 无
- 保密性 高
- 完整性 无
CWE-ID | 漏洞类型 |
CWE-59 | 在文件访问前对链接解析不恰当(链接跟随) |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论