Answer in brief
CVE-2023-23946 records a Medium severity (CVSS 6.2) vulnerability in Git's `git apply` overwriting paths outside the working tree. The current sources do not mark it as known exploited. The current feed maps git/git (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps git/git (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| git/gitgeneric | >=2.39.0 <2.39.2 || >=2.38.0 <2.38.4 || >=2.37.0 <2.37.6 || >=2.36.0 <2.36.5 || >=2.35.0 <2.35.7 || >=2.34.0 <2.34.7 || >=2.33.0 <2.33.7 || >=2.32.0 <2.32.6 || >=2.31.0 <2.31.7 || <2.30.8 | 2.30.8, 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7 |
Published upstream
Feb 14, 2023
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symbolic link.
Quoted source text, attributed separately from HOL analysis.