Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1387

Опубликовано: 10 дек. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

A flaw was discovered where git improperly validates submodules' names used to construct git metadata paths and does not prevent them from being nested in existing directories used to store another submodule's metadata. A remote attacker could abuse this flaw to trick a victim user into cloning a malicious repository containing submodules, which, when recursively cloned, would trigger the flaw and remotely execute code on the victim's machine.

Отчет

This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 as they did not use submodules names to construct git metadata paths.

Меры по смягчению последствий

Avoid running git clone --recurse-submodules and git submodule update with untrusted repositories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitNot affected
Red Hat Fuse 7camel-gitNot affected
Red Hat JBoss Fuse 6camel-gitNot affected
Red Hat Enterprise Linux 7gitFixedRHSA-2020:012416.01.2020
Red Hat Enterprise Linux 8gitFixedRHSA-2019:435619.12.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsgitFixedRHSA-2020:022827.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-git218-gitFixedRHSA-2020:000202.01.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1781127git: Remote code execution in recursive clones with nested submodules

EPSS

Процентиль: 86%
0.0317
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

CVSS3: 8.8
nvd
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

msrc
почти 6 лет назад

Git for Visual Studio Remote Code Execution Vulnerability

CVSS3: 8.8
debian
больше 5 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v ...

CVSS3: 8.8
github
больше 3 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

EPSS

Процентиль: 86%
0.0317
Низкий

7.5 High

CVSS3