CVE-2023-23946Medium· 6.2▾ TwilightPoC availableGit, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.1 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
2 GitHub repos (last check)
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to git apply, a path outside the working tree can be overwritten as the user who is running git apply. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use git apply --stat to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
git < 2.30.8git >= 2.31.0, < 2.31.7git >= 2.32.0, < 2.32.6git >= 2.33.0, < 2.33.7git >= 2.34.0, < 2.34.7git >= 2.35.0, < 2.35.7git >= 2.36.0, < 2.36.5git >= 2.37.0, < 2.37.6git >= 2.38.0, < 2.38.4git >= 2.39.0, < 2.39.2Upgrade past the affected range:
git 2.39.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-22490Medium· 5.5Git is a revision control system
CVE-2025-48384High· 8.0Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals
CVE-2021-21972Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
CVE-2019-19781Critical· 9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0
CVE-2020-3187Critical· 9.1A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
CVE-2021-40444High· 8.8Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows