---
cve: "CVE-2023-22490"
severity: "MEDIUM"
cvss: 5.5
epss: "71%"
vendor: "git"
kev: false
exploited: false
published: "2023-02-14 19:47:56"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T05:15:58+02:00"
---

# CVE-2023-22490

> 5.5 MEDIUM · 🧪 PoC

## Beschreibung

Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though Git will abort local clones whose source `$GIT_DIR/objects` directory contains symbolic links, the `objects` directory itself may still be a symbolic link. These two may be combined to include arbitrary files based on known paths on the victim's filesystem within the malicious repository's working copy, allowing for data exfiltration in a similar manner as CVE-2022-39253.

A fix has been prepared and will appear in v2.39.2 v2.38.4 v2.37.6 v2.36.5 v2.35.7 v2.34.7 v2.33.7 v2.32.6, v2.31.7 and v2.30.8. If upgrading is impractical, two short-term workarounds are available. Avoid cloning repositories from untrusted sources with `--recurse-submodules`. Instead, consider cloning repositories without recursively cloning their submodules, and instead run `git submodule update` at each layer. Before doing so, inspect each new `.gitmodules` file to ensure that it does not contain suspicious module URLs.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 2cfea1bdd7ee8ad1ca93f957c25d323a44dbd5c3 (Commit)
- a82fa99b36ddfd643e61ed45e52abe314687df67 (Commit)

## Referenzen

- <https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q>
- <https://github.com/git/git/security/advisories/GHSA-3wp6-j8xr-qw85>
- <https://github.com/git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd>
- <https://security.gentoo.org/glsa/202312-15>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-22490) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
