PT-2019-4871 · Git+3 · Git+3
Joern Schneeweisz
·
Published
2019-12-10
·
Updated
2024-06-15
·
CVE-2019-19604
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Git versions prior to 2.20.2
Git versions 2.21.x prior to 2.21.1
Git versions 2.22.x prior to 2.22.2
Git versions 2.23.x prior to 2.23.1
Git versions 2.24.x prior to 2.24.1
Description
The issue allows for arbitrary command execution because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository. This can enable a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations
For Git versions prior to 2.20.2, update to version 2.20.2 or later.
For Git versions 2.21.x prior to 2.21.1, update to version 2.21.1 or later.
For Git versions 2.22.x prior to 2.22.2, update to version 2.22.2 or later.
For Git versions 2.23.x prior to 2.23.1, update to version 2.23.1 or later.
For Git versions 2.24.x prior to 2.24.1, update to version 2.24.1 or later.
Exploit
Fix
RCE
Missing Authorization
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Git
Suse
Ubuntu