contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade git-emailUpgrade gitUpgrade git-debuginfoUpgrade git-p4Upgrade git-bzrUpgrade git-hgUpgrade git-svnUpgrade git-daemonUpgrade perl-Git-SVNUpgrade git-cvsUpgrade emacs-gitUpgrade perl-GitUpgrade git-allUpgrade gitkUpgrade gitwebUpgrade git-guiUpgrade emacs-git-el | Aug 28, 2019 | Mar 20, 2017 |
| Debian | — | Upgrade git | Jul 30, 2024 | Mar 20, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Oracle_linux | — | Upgrade git-svnUpgrade git-guiUpgrade perl-Git-SVNUpgrade git-bzrUpgrade git-daemonUpgrade git-cvsUpgrade emacs-git-elUpgrade git-emailUpgrade git-hgUpgrade perl-GitUpgrade gitUpgrade gitkUpgrade emacs-gitUpgrade gitwebUpgrade git-p4Upgrade git-all | Aug 8, 2017 | Apr 22, 2014 |
| Redhat_linux | — | Upgrade git-daemonUpgrade git-hgUpgrade gitkUpgrade git-p4Upgrade emacs-gitUpgrade git-debuginfoUpgrade git-guiUpgrade git-emailUpgrade perl-Git-SVNUpgrade perl-GitUpgrade git-allUpgrade git-svnUpgrade gitwebUpgrade git-bzrUpgrade gitUpgrade git-cvsUpgrade emacs-git-el | Aug 3, 2017 | Mar 19, 2017 |
| Ubuntu | — | Upgrade git | Mar 24, 2017 | Mar 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub