The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Sep 20, 2017 | Apr 13, 2016 |
| Debian | — | Upgrade git | Feb 2, 2016 | Jan 5, 2016 |
| Freebsd | — | Upgrade git-liteUpgrade gitUpgrade git-guiUpgrade git-subversion | Dec 10, 2025 | Oct 19, 2015 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Oct 30, 2017 | Apr 13, 2016 |
| Oracle Solaris | — | Upgrade developer/versioning/mercurial-27 to version 4.1.3-0.175.3.20.0.3.0 on Solaris 11.3Upgrade developer/versioning/mercurial to version 4.1.3-0.175.3.20.0.3.0 on Solaris 11.3Upgrade developer/versioning/git to version 2.7.4-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 13, 2016 |
| Oracle_linux | — | Upgrade git-bzrUpgrade git19-gitwebUpgrade git-svnUpgrade git-daemonUpgrade git19-git-hgUpgrade git-cvsUpgrade git19-git-daemonUpgrade perl-Git-SVNUpgrade git-emailUpgrade git19-gitkUpgrade git-guiUpgrade git-p4Upgrade git19-git-emailUpgrade git19-git-allUpgrade git19-emacs-git-elUpgrade git19-git-svnUpgrade git19-git-cvsUpgrade emacs-git-elUpgrade git19-git-bzrUpgrade git-allUpgrade perl-GitUpgrade git19-perl-GitUpgrade emacs-gitUpgrade git19-gitUpgrade gitwebUpgrade git-hgUpgrade git19-emacs-gitUpgrade git19-git-guiUpgrade git19-perl-Git-SVNUpgrade gitUpgrade gitk | Oct 16, 2024 | Apr 13, 2016 |
| Suse | — | Upgrade git-guiUpgrade git-emailUpgrade gitkUpgrade mercurialUpgrade git-svnUpgrade git-coreUpgrade git-archUpgrade gitUpgrade git-daemonUpgrade git-cvsUpgrade git-web | Jan 4, 2016 | Dec 19, 2015 |
| Ubuntu | — | Upgrade git | Dec 18, 2015 | Dec 15, 2015 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Apr 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub