contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade git-daemonUpgrade git-emailUpgrade git-p4Upgrade git-cvsUpgrade git-debuginfoUpgrade git-bzrUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-hgUpgrade gitUpgrade gitwebUpgrade perl-GitUpgrade emacs-gitUpgrade git-allUpgrade gitkUpgrade emacs-git-elUpgrade git-gui | Aug 28, 2019 | Mar 20, 2017 |
| Debian | — | Upgrade git | Jul 30, 2024 | Mar 20, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Oracle_linux | — | Upgrade git-guiUpgrade git-bzrUpgrade git-cvsUpgrade git-daemonUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-p4Upgrade emacs-gitUpgrade git-allUpgrade emacs-git-elUpgrade perl-GitUpgrade git-emailUpgrade gitwebUpgrade gitUpgrade gitkUpgrade git-hg | Aug 8, 2017 | Apr 22, 2014 |
| Redhat_linux | — | Upgrade git-p4Upgrade gitkUpgrade git-debuginfoUpgrade git-guiUpgrade perl-Git-SVNUpgrade git-hgUpgrade emacs-gitUpgrade git-emailUpgrade git-daemonUpgrade git-bzrUpgrade emacs-git-elUpgrade git-svnUpgrade perl-GitUpgrade gitwebUpgrade git-allUpgrade git-cvsUpgrade git | Aug 3, 2017 | Mar 19, 2017 |
| Ubuntu | — | Upgrade git | Mar 24, 2017 | Mar 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub