Bug 2107439 (CVE-2022-29187)
Summary: | CVE-2022-29187 git: Bypass of safe.directory protections | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | amahdal, besser82, caswilli, chazlett, chrisw, dhalasz, dkuc, fjansen, hhorak, jburrell, jkoehler, johannes, jorton, jwong, jwon, kaycoth, kshier, opohorel, pjindal, pstodulk, sbalasub, sebastian.kisela, sthirugn, tmz, vkrizan, vmugicag |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | git 2.30.5, git 2.31.4, git 2.32.3, git 2.33.4, git 2.34.4, git 2.35.4, git 2.36.2, git 2.37.1 | Doc Type: | If docs needed, set a value |
Doc Text: |
A vulnerability was found in Git. This flaw occurs due to Git not checking the ownership of directories in a local multi-user system when running commands specified in the local repository configuration. This issue allows the owner of the repository to cause arbitrary commands to be executed by other users who access the repository.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2023-05-16 14:48:35 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2107450, 2107451, 2107452 | ||
Bug Blocks: | 2107214 |
Description
Sandipan Roy
2022-07-15 04:49:46 UTC
Created git tracking bugs for this issue: Affects: fedora-all [bug 2107450] This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:2319 https://access.redhat.com/errata/RHSA-2023:2319 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:2859 https://access.redhat.com/errata/RHSA-2023:2859 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-29187 The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days |