Aller au contenu principal
HIGH

CVE-2022-23642

CVSS v3

8.8

HIGH

Score EPSS

74.3 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.

Détails techniques

Publiée le
2022-02-18
Exploit-DB
EDB-50964

Questions fréquentes

Qu’est-ce que CVE-2022-23642 ?

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.

CVE-2022-23642 est-elle activement exploitée ?

Aucune exploitation active de CVE-2022-23642 n’est confirmée. Son score EPSS était de 74.3 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2022-23642 ?

CVE-2022-23642 a un score de base CVSS v3 de 8.8 (gravité HIGH).

CVE-2022-23642 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite