Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39253

21
FAUCET Score

CVE-2022-39253 is a sensitive information disclosure vulnerability affecting Git versions prior to 2.30.6 and various later patch releases, impacting products like Apple, Debian, Fedora, and Git-SCM. A malicious actor can trick a victim into cloning a specially crafted repository containing a symbolic link, leading to the exposure of sensitive local files. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring user interaction, but with high confidentiality impact. While there is no evidence of active exploitation, exploit code, or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.30.6CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.31.0, < 2.31.5CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.32.0, < 2.32.4CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.33.0, < 2.33.5CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.34.0, < 2.34.5CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.34%
Probability of exploitation in next 30 days
EPSS Percentile
68.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0134 is in the 79th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.2Fixed in: 17.2.10
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.21
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.3Fixed in: 17.3.7
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.0Fixed in: 17.0.16
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.51
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: git-0:2.39.1-1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: git-0:2.31.8-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: git-0:2.39.1-1.el9
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-git227-git

Vendor Advisories (2)

microsoft2022-Nov/CVE-2022-39253Important

GitHub: CVE-2022-39253 Local clone optimization dereferences symbolic links by default

Nov 8, 2022
redhatCVE-2022-39253Moderate

git: exposure of sensitive information to a malicious actor

Oct 18, 2022

References

seclists.org / fulldisclosure/2022/Nov/1
Mailing ListThird Party Advisory
github.com / git/git/security/advisories/GHSA-3wp6-j8xr-qw85
MitigationThird Party Advisory
lists.debian.org / debian-lts-announce/2022/12/msg00025.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/C7B6JPKX5CGGLAHXJVQMIZNNEEB72FHD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JMQWGMDLX6KTVWW5JZLVPI7ICAK72TN7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OHNO2FB55CPX47BAXMBWUBGWHO6N6ZZH
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UKFHE4KVD7EKS5J3KTDFVBEKU3CLXGVV
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VFYXCTLOSESYIP72BUYD6ECDIMUM4WMB
security.gentoo.org / glsa/202312-15
support.apple.com / kb/HT213496
Third Party Advisory
openwall.com / lists/oss-security/2023/02/14/5
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2024/05/14/2