contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade git-cvsUpgrade gitUpgrade git-debuginfoUpgrade git-bzrUpgrade perl-Git-SVNUpgrade git-hgUpgrade git-svnUpgrade git-p4Upgrade git-daemonUpgrade git-emailUpgrade git-guiUpgrade emacs-gitUpgrade emacs-git-elUpgrade gitwebUpgrade gitkUpgrade perl-GitUpgrade git-all | Aug 28, 2019 | Mar 20, 2017 |
| Debian | — | Upgrade git | Jul 30, 2024 | Mar 20, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Nov 30, 2017 | Mar 19, 2017 |
| Oracle_linux | — | Upgrade git-emailUpgrade emacs-gitUpgrade perl-GitUpgrade git-hgUpgrade gitkUpgrade gitUpgrade gitwebUpgrade git-p4Upgrade git-allUpgrade emacs-git-elUpgrade git-bzrUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-cvsUpgrade git-daemonUpgrade git-gui | Aug 8, 2017 | Apr 22, 2014 |
| Redhat_linux | — | Upgrade perl-Git-SVNUpgrade git-hgUpgrade gitkUpgrade emacs-gitUpgrade git-daemonUpgrade git-debuginfoUpgrade git-guiUpgrade git-p4Upgrade git-emailUpgrade gitwebUpgrade git-cvsUpgrade git-svnUpgrade emacs-git-elUpgrade gitUpgrade git-bzrUpgrade perl-GitUpgrade git-all | Aug 3, 2017 | Mar 19, 2017 |
| Ubuntu | — | Upgrade git | Mar 24, 2017 | Mar 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub