contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade emacs-gitUpgrade gitwebUpgrade perl-GitUpgrade gitkUpgrade git-allUpgrade emacs-git-elUpgrade git-guiUpgrade perl-Git-SVNUpgrade git-bzrUpgrade git-emailUpgrade git-debuginfoUpgrade git-p4Upgrade gitUpgrade git-svnUpgrade git-hgUpgrade git-cvsUpgrade git-daemon | Aug 28, 2019 | Mar 20, 2017 |
| Debian | — | Upgrade git | Jul 30, 2024 | Mar 20, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Oracle_linux | — | Upgrade git-bzrUpgrade perl-Git-SVNUpgrade git-daemonUpgrade git-svnUpgrade git-guiUpgrade git-cvsUpgrade gitkUpgrade git-allUpgrade gitwebUpgrade git-p4Upgrade git-emailUpgrade emacs-gitUpgrade emacs-git-elUpgrade git-hgUpgrade perl-GitUpgrade git | Aug 8, 2017 | Apr 22, 2014 |
| Redhat_linux | — | Upgrade git-hgUpgrade git-emailUpgrade git-p4Upgrade git-guiUpgrade git-daemonUpgrade gitkUpgrade emacs-gitUpgrade perl-Git-SVNUpgrade git-debuginfoUpgrade git-svnUpgrade gitUpgrade git-cvsUpgrade git-bzrUpgrade perl-GitUpgrade gitwebUpgrade git-allUpgrade emacs-git-el | Aug 3, 2017 | Mar 19, 2017 |
| Ubuntu | — | Upgrade git | Mar 24, 2017 | Mar 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub