CVE-2023-29011
Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. The location of `connect.exe`'s config file is hard-coded as `/etc/connectrc` which will typically be interpreted as `C:\etc\connectrc`. Since `C:\etc` can be created by any authenticated user, this makes `connect.exe` susceptible to malicious files being placed there by other users on the same multi-user machine. The problem has been patched in Git for Windows v2.40.1. As a workaround, create the folder `etc` on all drives where Git commands are run, and remove read/write access from those folders. Alternatively, watch out for malicious `<drive>:\etc\connectrc` files on multi-user machines.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- git for windows project/git for windows
- Source
- security-advisories@github.com
References
- https://github.com/git-for-windows/git/releases/tag/v2.40.1.windows.1Release Notes
- https://github.com/git-for-windows/git/security/advisories/GHSA-g4fv-xjqw-q7jmVendor Advisory
- https://github.com/git-for-windows/git/releases/tag/v2.40.1.windows.1Release Notes
- https://github.com/git-for-windows/git/security/advisories/GHSA-g4fv-xjqw-q7jmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.