#VU75486 Input validation error in Git for Windows - CVE-2023-29007
Published: April 25, 2023 / Updated: August 16, 2024
Git for Windows
Git for Windows
Description
The vulnerability allows an attacker to tamper with Git configuration.
The vulnerability exists due to insufficient input validation in "git submodule deinit" when renaming or deleting a section from a configuration file. A remote attacker can trick the victim into running the command a malicious configuration file and tamper with Git configuration on the affected system.