HIGH

CVE-2022-23642

CVSS v3

8.8

HIGH

EPSS Score

83.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.

Technical details

Published
2/18/2022

Frequently asked questions

What is CVE-2022-23642?

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.

Is CVE-2022-23642 actively exploited?

Active exploitation of CVE-2022-23642 has not been confirmed. The EPSS score is 83.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-23642?

CVE-2022-23642 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-23642 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.