CVE-2023-25815 is a low-severity vulnerability affecting Git for Windows versions prior to 2.40.1, where a change in gettext initialization allows low-privilege local users to place malicious localized messages in a hard-coded path. This could lead to social engineering attacks by displaying fake messages to users. The attack requires local write access and user interaction, making it difficult to exploit. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.40.1CPE matchmatch criteria | cpe:2.3:a:git_for_windows_project:git_for_windows:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.