Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1349

Опубликовано: 10 дек. 2019
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

An improper input validation flaw was discovered in git in the way it handles git submodules. A remote attacker could abuse this flaw to trick a victim user into recursively cloning a malicious repository, which, under certain circumstances, could fool git into using the same git directory twice and potentially cause remote code execution.

Меры по смягчению последствий

Avoid running git clone --recurse-submodules and git submodule update with untrusted repositories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitNot affected
Red Hat Enterprise Linux 7gitWill not fix
Red Hat Fuse 7camel-gitNot affected
Red Hat JBoss Fuse 6camel-gitNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected
Red Hat Enterprise Linux 8gitFixedRHSA-2019:435619.12.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsgitFixedRHSA-2020:022827.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1781143git: Recursive submodule cloning allows using git directory twice with synonymous directory name written in .git/

EPSS

Процентиль: 95%
0.19352
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

CVSS3: 8.8
nvd
больше 5 лет назад

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

msrc
почти 6 лет назад

Git for Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.8
debian
больше 5 лет назад

A remote code execution vulnerability exists when Git for Visual Studi ...

github
больше 3 лет назад

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

EPSS

Процентиль: 95%
0.19352
Средний

7.5 High

CVSS3