Known vulnerabilities in git (Red Hat package)
Vendor:
Red Hat Inc.
Software:
git (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:git_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
29
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
2.31.8-3.el8_6.1
2.27.0-5.el8_4.1
2.31.1-6.el9_0.1
2.39.5-1.el9_2.2
2.39.5-1.el8_8.2
2.18.4-5.el8_2.1
1.8.3.1-25.el7_9.1
2.43.5-1.el9_4.2
2.43.7-1.el8_10
2.47.3-1.el10_0
2.47.3-1.el9_6
2.43.5-3.el8_10
2.39.5-1.el9_2.1
2.43.5-1.el9_4.1
2.47.1-2.el9_6
1.7.1-4.el6_7.1
2.18.4-5.el8_2
2.31.1-6.el9_0
2.39.5-1.el8_8
2.43.5-1.el8_10
2.43.5-1.el9_4
1.7.1-3.el6_4.1
1.7.1-2.el6_0.1
2.18.4-4.el8_2
1.8.3.1-25.el7_9
2.27.0-4.el8_4
2.39.3-1.el9_2
2.39.3-1.el8_8
2.31.1-4.el8_6
2.31.1-5.el9_0
2.18.4-3.el8_1
2.39.1-1.el8
2.39.1-1.el9
1.8.3.1-24.el7_9
2.31.1-3.el9_0
2.31.1-3.el8_6
2.27.0-3.el8_4
2.18.4-2.el8_1
2.18.4-3.el8_2
2.31.1-3.el8_7
2.31.1-3.el9_1
2.18.2-2.el8_0
1.8.3.1-22.el7_8
1.8.3.1-23.el7_7
2.18.2-2.el8_1
1.8.3.1-23.el7_8
2.18.4-1.el8_1
2.18.4-2.el8_2
2.18.4-1.el8_0
2.18.2-1.el8_0
1.8.3.1-21.el7_7
2.18.2-1.el8_1
1.8.3.1-20.el7
1.8.3.1-14.el7_5
1.8.3.1-12.el7_4
1.8.3.1-11.el7
1.8.3.1-6.el7
1.7.1-10.el6_10
1.7.1-9.el6_9
1.7.1-8.el6
1.7.1-4.el6_7
1.7.1-3.el6_4
1.7.1-2.el6_0
1.7.1-2.el6
Vulnerabilities (29)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112646 - Product UI does not Warn User of Unsafe Actions CVE-2025-46835 |
CWE-356 | Medium | 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 09.07.2025 |
SB2025070994 SB20250709121 SB2025071019 and 22 more |
||
| #VU112643 - Improper input validation CVE-2025-27614 |
CWE-20 | High | 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 09.07.2025 |
SB2025070994 SB20250709119 SB2025071019 and 18 more |
||
| #VU112642 - Protection Mechanism Failure CVE-2025-27613 |
CWE-693 | High | 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 09.07.2025 |
SB2025070994 SB20250709122 SB2025071019 and 22 more |
||
| #VU112638 - Improper input validation CVE-2025-48385 |
CWE-20 | High | 2.39.5-1.el8_8.2, 2.39.5-1.el9_2.2, 2.43.5-1.el9_4.2, 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 09.07.2025 |
SB2025070989 SB2025070990 SB2025070991 and 38 more |
||
| #VU112637 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2025-48384 |
CWE-93 | Medium | 1.8.3.1-25.el7_9.1, 2.18.4-5.el8_2.1, 2.27.0-5.el8_4.1, 2.31.1-6.el9_0.1, 2.31.8-3.el8_6.1, 2.39.5-1.el8_8.2, 2.39.5-1.el9_2.2, 2.43.5-1.el9_4.2, 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 09.07.2025 |
SB2025070989 SB2025070990 SB2025070991 and 52 more |
||
| #VU102871 - Improper Encoding or Escaping of Output CVE-2024-52005 |
CWE-116 | Medium | 2.39.5-1.el9_2.1, 2.43.5-1.el9_4.1, 2.43.5-3.el8_10, 2.47.1-2.el9_6 | 16.01.2025 |
SB2025011641 SB2025021457 SB2025051343 and 18 more |
||
| #VU102870 - Improper Encoding or Escaping of Output CVE-2024-50349 |
CWE-116 | Low | 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 16.01.2025 |
SB2025011640 SB2025011641 SB2025011643 and 21 more |
||
| #VU102869 - Improper Encoding or Escaping of Output CVE-2024-52006 |
CWE-116 | Low | 2.43.7-1.el8_10, 2.47.3-1.el9_6, 2.47.3-1.el10_0 | 16.01.2025 |
SB2025011640 SB2025011641 SB2025011643 and 21 more |
||
| #VU91288 - Improper Control of Generation of Code ('Code Injection') CVE-2024-32465 |
CWE-94 | High | 2.43.5-1.el8_10, 2.43.5-1.el9_4 | 07.06.2024 |
SB2024060720 SB2024060721 SB2024060723 and 44 more |
||
| #VU91287 - UNIX Symbolic Link (Symlink) Following CVE-2024-32021 |
CWE-61 | Medium | 2.43.5-1.el8_10, 2.43.5-1.el9_4 | 07.06.2024 |
SB2024060720 SB2024060721 SB2024060723 and 44 more |
||
| #VU91286 - UNIX Hard Link CVE-2024-32020 |
CWE-62 | Medium | 2.43.5-1.el8_10, 2.43.5-1.el9_4 | 07.06.2024 |
SB2024060720 SB2024060721 SB2024060723 and 43 more |
||
| #VU89491 - Unrestricted Upload of File with Dangerous Type CVE-2024-32002 |
CWE-434 | High | 2.31.1-6.el9_0, 2.39.5-1.el8_8, 2.43.5-1.el8_10, 2.43.5-1.el9_4 | 15.05.2024 |
SB2024051504 SB2024060720 SB2024060721 and 52 more |
||
| #VU89490 - Improper Control of Generation of Code ('Code Injection') CVE-2024-32004 |
CWE-94 | High | 2.18.4-5.el8_2, 2.31.1-6.el9_0, 2.39.5-1.el8_8, 2.43.5-1.el8_10, 2.43.5-1.el9_4 | 15.05.2024 |
SB2024051503 SB2024060720 SB2024060721 and 51 more |
||
| #VU75486 - Improper input validation CVE-2023-29007 |
CWE-20 | Low | 1.8.3.1-25.el7_9, 2.18.4-3.el8_1, 2.18.4-4.el8_2, 2.27.0-4.el8_4, 2.31.1-4.el8_6, 2.31.1-5.el9_0, 2.39.3-1.el8_8, 2.39.3-1.el9_2 | 25.04.2023 |
SB2023042553 SB2023042610 SB2023042629 and 48 more |
||
| #VU75485 - Insufficient Verification of Data Authenticity CVE-2023-25815 |
CWE-345 | Low | 2.18.4-3.el8_1, 2.18.4-4.el8_2, 2.27.0-4.el8_4, 2.31.1-4.el8_6, 2.31.1-5.el9_0, 2.39.3-1.el8_8, 2.39.3-1.el9_2 | 25.04.2023 |
SB2023042553 SB2023042610 SB2023042638 and 40 more |
||
| #VU75484 - Improper Link Resolution Before File Access ('Link Following') CVE-2023-25652 |
CWE-59 | Low | 1.8.3.1-25.el7_9, 2.18.4-3.el8_1, 2.18.4-4.el8_2, 2.27.0-4.el8_4, 2.31.1-4.el8_6, 2.31.1-5.el9_0, 2.39.3-1.el8_8, 2.39.3-1.el9_2 | 25.04.2023 |
SB2023042553 SB2023042610 SB2023042629 and 48 more |
||
| #VU72246 - Improper Link Resolution Before File Access ('Link Following') CVE-2023-22490 |
CWE-59 | Low | 2.39.3-1.el8_8, 2.39.3-1.el9_2 | 15.02.2023 |
SB2023021529 SB2023021528 SB2023021533 and 31 more |
||
| #VU72245 - Improper Link Resolution Before File Access ('Link Following') CVE-2023-23946 |
CWE-59 | Medium | 2.39.3-1.el8_8, 2.39.3-1.el9_2 | 15.02.2023 |
SB2023021529 SB2023021528 SB2023021533 and 28 more |
||
| #VU68518 - Heap-based Buffer Overflow CVE-2022-39260 |
CWE-122 | High | 2.39.1-1.el8, 2.39.1-1.el9 | 19.10.2022 |
SB2022101995 SB2022101996 SB2022101997 and 23 more |
||
| #VU65287 - Permissions, Privileges, and Access Controls CVE-2022-29187 |
CWE-264 | Medium | 2.39.1-1.el8, 2.39.1-1.el9 | 13.07.2022 |
SB2022071347 SB2022071348 SB2022071350 and 30 more |
Showing elements 1 - 20 out of 29