In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Jun 13, 2018 | May 30, 2018 |
| Amazon Linux Ami 2 | — | Upgrade git-p4Upgrade gitkUpgrade gitUpgrade perl-Git-SVNUpgrade git-coreUpgrade git-debuginfoUpgrade git-emailUpgrade git-core-docUpgrade gitwebUpgrade git-guiUpgrade git-daemonUpgrade git-cvsUpgrade git-allUpgrade git-gnome-keyringUpgrade perl-GitUpgrade git-svn | Apr 27, 2020 | May 30, 2018 |
| Amazon_linux | — | Upgrade git | Jun 12, 2018 | May 29, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 30, 2018 |
| Centos_linux | — | Upgrade git-guiUpgrade gitwebUpgrade git-bzrUpgrade git-cvsUpgrade perl-GitUpgrade git-daemonUpgrade git-svnUpgrade git-debuginfoUpgrade git-allUpgrade git-emailUpgrade perl-Git-SVNUpgrade git-p4Upgrade gitUpgrade git-hgUpgrade gitkUpgrade emacs-git-elUpgrade emacs-git | Jun 26, 2018 | May 29, 2018 |
| Debian | — | Upgrade git | May 31, 2018 | May 29, 2018 |
| Freebsd | — | Upgrade libgit2Upgrade py-pygit2Upgrade git-liteUpgrade git | Jun 5, 2018 | Jun 5, 2018 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | May 30, 2018 | May 30, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Jul 3, 2018 | May 30, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Jul 3, 2018 | May 30, 2018 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.15.2-0.175.3.34.0.2.0 on Solaris 11.3 | Jul 18, 2018 | May 30, 2018 |
| Oracle_linux | — | Upgrade git-hgUpgrade git-bzrUpgrade git-p4Upgrade emacs-git-elUpgrade git-guiUpgrade gitwebUpgrade perl-Git-SVNUpgrade gitkUpgrade git-daemonUpgrade perl-GitUpgrade emacs-gitUpgrade git-cvsUpgrade git-allUpgrade git-svnUpgrade git-emailUpgrade git | Jun 21, 2018 | May 30, 2018 |
| Redhat_linux | — | Upgrade emacs-git-elUpgrade perl-GitUpgrade gitwebUpgrade git-debuginfoUpgrade git-emailUpgrade git-p4Upgrade git-daemonUpgrade git-allUpgrade git-guiUpgrade emacs-gitUpgrade perl-Git-SVNUpgrade gitUpgrade git-bzrUpgrade git-cvsUpgrade git-hgUpgrade gitkUpgrade git-svn | Jun 21, 2018 | May 29, 2018 |
| Suse | — | Upgrade git-credential-gnome-keyringUpgrade git-webUpgrade libgit2-26-32bitUpgrade libgit2-28Upgrade git-guiUpgrade libgit2-develUpgrade gitkUpgrade gitUpgrade git-credential-libsecretUpgrade libgit2-26Upgrade git-coreUpgrade git-cvsUpgrade git-archUpgrade git-emailUpgrade libgit2-24Upgrade git-svnUpgrade git-docUpgrade git-daemonUpgrade git-p4 | Jun 6, 2018 | May 29, 2018 |
| Ubuntu | — | Upgrade git | Jun 12, 2018 | May 29, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 30, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub