CVE-2023-29007 Details
Description
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary configuration into a user's `$GIT_DIR/config` when attempting to remove the configuration section associated with that submodule. When the attacker injects configuration values which specify executables to run (such as `core.pager`, `core.editor`, `core.sshCommand`, etc.) this can lead to a remote code execution. A fix A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid running `git submodule deinit` on untrusted repositories or without prior inspection of any submodule sections in `$GIT_DIR/config`.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| git-scm git | < 2.30.9 >= 2.31.0, < 2.31.8 >= 2.32.0, < 2.32.7 >= 2.33.0, < 2.33.8 >= 2.34.0, < 2.34.8 >= 2.35.0, < 2.35.8 >= 2.36.0, < 2.36.5 >= 2.37.0, < 2.37.7 >= 2.38.0, < 2.38.5 >= 2.39.0, < 2.39.3 2.40.0 |
CPE
Remediation
| |
| fedoraproject fedora | 36 37 38 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 26, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 1, 2024 | Modified Analysis | [email protected] |
| Dec 27, 2023 | CVE Modified | [email protected] |
| May 12, 2023 | CVE Modified | [email protected] |
| May 4, 2023 | Initial Analysis | [email protected] |
| May 1, 2023 | CVE Modified | [email protected] |
| Apr 28, 2023 | CVE Modified | [email protected] |