Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2019/12/13/1 - Mailing List, Third Party Advisory | |
References | () https://gitlab.com/gitlab-com/gl-security/disclosures/blob/master/003_git_submodule/advisory.md - Exploit, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCYSSCA5ZTEP46SB4XRPSQGFV2L3NKMZ/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N6UGTEOXWIYSM5KDZL74QD2GK6YQNQCP/ - | |
References | () https://public-inbox.org/git/xmqqr21cqcn9.fsf%40gitster-ct.c.googlers.com/ - | |
References | () https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.24.1.txt - Third Party Advisory | |
References | () https://security.gentoo.org/glsa/202003-30 - Third Party Advisory | |
References | () https://www.debian.org/security/2019/dsa-4581 - Third Party Advisory |
07 Nov 2023, 03:07
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-12-11 00:15
Updated : 2024-11-21 04:35
NVD link : CVE-2019-19604
Mitre link : CVE-2019-19604
CVE.ORG link : CVE-2019-19604
JSON object : View
Products Affected
opensuse
- leap
git-scm
- git
fedoraproject
- fedora
debian
- debian_linux