GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Feb 9, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Nov 19, 2019 | Feb 9, 2018 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.15.2-0.175.3.34.0.2.0 on Solaris 11.3 | Jul 18, 2018 | Feb 9, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 9, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Feb 9, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub