Skip to content

gitk can inadvertently call executables in the worktree

High
derrickstolee published GHSA-wxwv-49qw-35pm Feb 14, 2023

Package

git-for-windows

Affected versions

<=2.39.1

Patched versions

2.39.2

Description

Impact

When gitk is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code.

Patches

Workarounds

Avoid using gitk (or Git GUI's "Visualize History" functionality) in clones of untrusted repositories.

References

Severity

High
8.6
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVE ID

CVE-2023-23618

Weaknesses

Credits