CVE-2022-24975

SOURCE - nist

Summary

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

EPSS Score: 0.00224 (0.605)

Common Weakness Enumeration (CWE)

SOURCE - nist

Exposure of Resource to Wrong Sphere

SOURCE - redhat

Exposure of Sensitive Information to an Unauthorized Actor


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/gitdebdebian12>=1:2.39.2-1.1Not yet available
debian/gitdebdebianunstable>=1:2.43.0-1Not yet available
debian/gitdebdebian13>=1:2.43.0-1Not yet available
debian/gitdebdebian10>=1:2.20.1-2+deb10u3Not yet available
debian/gitdebdebian11>=1:2.30.2-1+deb11u2Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7.5low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5low

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE