← Back

CVE-2019-1387

nvd nist
Published: Dec 18, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

Affected (11)

Products: Git Scm: Git
1 product
Git
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Git Scm
From 2.14.0 to 2.14.6
From 2.15.0 to 2.15.4
From 2.16.0 to 2.16.6
From 2.17.0 to 2.17.3
From 2.18.0 to 2.18.2
From 2.19.0 to 2.19.3
From 2.20.0 to 2.20.2
From 2.22.0 to 2.22.2
Version 2.21.0
Version 2.23.0
Version 2.24.0

References (27)

Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.