SCA: security update for github.com/git-lfs/git-lfs/v3 (GHSA-6rw3-3whw-jvjj)

high Tenable Self-Hosted Container Security Plugin ID 411619

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named
`git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the
attacker to execute arbitrary code. This does not affect Unix systems. Similarly, if the malicious
repository contains files named `..exe` and `cygpath.exe`, and `cygpath.exe` is not found in `PATH`, the
`..exe` program will be executed when certain Git LFS commands are run. More generally, if the current
working directory contains any file with a base name of `.` and a file extension from `PATHEXT` (except
`.bat` and `.cmd`), and also contains another file with the same base name as a program Git LFS intends to
execute (such as `git`, `cygpath`, or `uname`) and any file extension from `PATHEXT` (including `.bat` and
`.cmd`), then, on Windows, when Git LFS attempts to execute the intended program the `..exe`, `..com`,
etc., file will be executed instead, but only if the intended program is not found in any directory listed
in `PATH`. The vulnerability occurs because when Git LFS detects that the program it intends to run does
not exist in any directory listed in `PATH` then Git LFS passes an empty string as the executable file
path to the Go `os/exec` package, which contains a bug such that, on Windows, it prepends the name of the
current working directory (i.e., `.`) to the empty string without adding a path separator, and as a result
searches in that directory for a file with the base name `.` combined with any file extension from
`PATHEXT`, executing the first one it finds. (The reason `..bat` and `..cmd` files are not executed in the
same manner is that, although the Go `os/exec` package tries to execute them just as it does a `..exe`
file, the Microsoft Win32 API `CreateProcess()` family of functions have an undocumented feature in that
they apparently recognize when a caller is attempting to execute a batch script file and instead run the
`cmd.exe` command interpreter, passing the full set of command line arguments as parameters. These are
unchanged from the command line arguments set by Git LFS, and as such, the intended program's name is the
first, resulting in a command line like `cmd.exe /c git`, which then fails.) Git LFS has resolved this
vulnerability by always reporting an error when a program is not found in any directory listed in `PATH`
rather than passing an empty string to the Go `os/exec` package in this case. The bug in the Go `os/exec`
package has been reported to the Go project and is expected to be patched after this security advisory is
published. The problem was introduced in version 2.12.1 and is patched in version 3.1.3. Users of affected
versions should upgrade to version 3.1.3. There are currently no known workarounds at this time.
(CVE-2022-24826)

See Also

https://github.com/advisories/GHSA-6rw3-3whw-jvjj

Plugin Details

Severity: High

ID: 411619

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 97.35

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.3

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-24826

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/22/2022

Vulnerability Publication Date: 4/19/2022

Reference Information

CVE: CVE-2022-24826

cwe: CWE-426