Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 22, 2024 | Dec 10, 2019 |
| Amazon Linux Ami 2 | — | Upgrade git-coreUpgrade perl-Git-SVNUpgrade gitwebUpgrade git-svnUpgrade git-subtreeUpgrade git-guiUpgrade git-instawebUpgrade git-daemonUpgrade git-allUpgrade git-emailUpgrade git-core-docUpgrade git-p4Upgrade git-cvsUpgrade git-debuginfoUpgrade perl-GitUpgrade gitkUpgrade git | Apr 27, 2020 | Dec 11, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 10, 2019 |
| Debian | — | Upgrade git | Jul 30, 2024 | Dec 11, 2019 |
| Freebsd | — | Upgrade gitlab-ce | Dec 11, 2019 | Dec 10, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | Feb 24, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | Feb 26, 2020 | Dec 11, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Dec 11, 2019 |
| Suse | — | Upgrade git-emailUpgrade gitkUpgrade git-p4Upgrade git-guiUpgrade git-cvsUpgrade perl-Authen-SASLUpgrade git-credential-gnome-keyringUpgrade git-archUpgrade git-svnUpgrade perl-Net-SMTP-SSLUpgrade git-webUpgrade git-daemonUpgrade git-credential-libsecretUpgrade gitUpgrade git-docUpgrade git-core | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub