已开启
CVE-2022-24975 #79
openeuler-ci-bot创建于  2022年2月23日
openeuler-ci-bot
openeuler-ci-bot成员
2022年2月23日 创建

一、漏洞信息
漏洞编号:CVE-2022-24975
漏洞归属组件:git
漏洞归属的版本:2.23.0,2.27.0,2.30.0,2.33.0
CVSS V3.0分值:
BaseScore:7.5 High
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞简述:
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the GitBleed issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option.
漏洞公开时间:2022-02-12 04:15
漏洞创建时间:2022-02-23 08:14:42
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2022-24975

更多参考(点击展开)
参考来源 参考链接 来源链接
MISC https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/
MISC https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191
nvd https://access.redhat.com/security/cve/CVE-2022-24975
redhat_bugzilla https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/
debian https://security-tracker.debian.org/tracker/CVE-2022-24975

漏洞分析指导链接:
https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
其它
漏洞补丁信息:

详情(点击展开)

二、漏洞分析结构反馈
影响性分析说明:
在Git中发现了一个被称为 GitBleed 的缺陷,通过 -mirror 选项克隆的仓库,如果没有提前适当地删除,可能会泄露秘密或敏感信息。这个缺陷允许攻击者利用Git行为中的这一差异,找到公共仓库中隐藏的秘密和其他敏感数据。影响机密性和可用性。
openEuler评分:
7.5
Vector:CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
受影响版本排查(受影响/不受影响):
1.openEuler-20.03-LTS-SP1(2.27.0):受影响
2.openEuler-20.03-LTS-SP2(2.27.0):受影响
3.openEuler-20.03-LTS-SP3(2.27.0):受影响
4.openEuler-Mainline:受影响
5.openEuler-22.03:LTS:受影响
6.openEuler-22.03:LTS:Next:受影响
7.openEuler-24.03-LTS-Next(2.43.0):
8.openEuler-22.03-LTS-SP4(2.33.0):
9.openEuler-24.03-LTS-SP2(2.43.0):

修复是否涉及abi变化(是/否):
1.openEuler-20.03-LTS-SP1(2.27.0):否
2.openEuler-20.03-LTS-SP2(2.27.0):否
3.openEuler-20.03-LTS-SP3(2.27.0):否
4.openEuler-Mainline:否
5.openEuler-22.03:LTS:否
6.openEuler-22.03:LTS:Next:否
7.openEuler-24.03-LTS-Next(2.43.0):
8.openEuler-22.03-LTS-SP4(2.33.0):
9.openEuler-24.03-LTS-SP2(2.43.0):

原因说明:
1.master(2.49.0):
2.openEuler-20.03-LTS-SP4(2.27.0):
3.openEuler-22.03-LTS-SP3(2.33.0):
4.openEuler-22.03-LTS-SP4(2.33.0):
5.openEuler-24.03-LTS(2.43.0):
6.openEuler-24.03-LTS-Next(2.43.0):
7.openEuler-24.03-LTS-SP1(2.43.0):
8.openEuler-24.03-LTS-SP2(2.43.0):

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2022年2月23日 创建了CVE和安全问题
openeuler-ci-botopeneuler-ci-bot成员
2022年2月23日 添加了   CVE/UNFIXED 标签
openeuler-ci-bot
openeuler-ci-bot成员
2022年2月23日 评论:

@xiezhipeng1 ,@overweight ,@hanxinke ,@zhuchunyi ,@zhujianwei001 ,@openeuler-basic ,@pecs ,@yanan-rock ,@licihua ,@miao_kaibo
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, openEuler评分, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后cve-manager将无法正常解析填写内容.


影响性分析说明:

openEuler评分: (评分和向量)

受影响版本排查(受影响/不受影响):
1.openEuler-20.03-LTS-SP1(2.27.0):
2.openEuler-20.03-LTS-SP2(2.27.0):
3.openEuler-20.03-LTS-SP3(2.27.0):

修复是否涉及abi变化(是/否):
1.openEuler-20.03-LTS-SP1(2.27.0):
2.openEuler-20.03-LTS-SP2(2.27.0):
3.openEuler-20.03-LTS-SP3(2.27.0):


issue处理具体操作请参考:
https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
pr关联issue具体操作请参考:
https://gitee.com/help/articles/4142

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
2022年2月23日 评论:

Hi openeuler-ci-bot, welcome to the openEuler Community.
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here.
If you have any questions, please contact the SIG: Base-service, and any of the maintainers: @xiezhipeng1 , @overweight , @hanxinke , @zhuchunyi , @zhujianwei001 , @openeuler-basic , @pecs , @yanan-rock , @licihua , @miao_kaibo

likedislike
openeuler-ci-botopeneuler-ci-bot成员
2022年2月23日 添加了   sig/Base-service 标签
此处折叠了47条消息 查看更多
openeuler-ci-bot
openeuler-ci-bot成员
2024年9月10日 评论:
issue状态 操作者 原因
已挂起 xieminmin git工具本身无漏洞,该CVE需要代码仓分析删除敏感信息,无法从git侧修复。
likedislike
openeuler-ci-botopeneuler-ci-bot成员
2025年4月14日 修改了描述
2025年7月24日 评论:

是否可以将git升级到2.35.1版本以此修复此漏洞

likedislike
2025年7月24日 评论:

是否可以将git升级到2.35.1版本以此修复此漏洞

该漏洞git无法修复,不存在修复版本,2.35.1版本的--mirror特性反而会让攻击者获取更多的机敏信息:
2024年7月AquaSec就此漏洞发表了更深入的博客文章:https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/
输入图片说明

likedislike
2025年7月25日 评论:

是否可以将git升级到2.35.1版本以此修复此漏洞

好的,感谢

likedislike