A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2Upgrade gitUpgrade libgit2-1.0Upgrade libgit2-1.1 | Aug 22, 2024 | Jan 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-cvsUpgrade git-svnUpgrade gitUpgrade git-allUpgrade git-subtreeUpgrade gitwebUpgrade git-debuginfoUpgrade gitkUpgrade git-p4Upgrade perl-GitUpgrade git-coreUpgrade git-core-docUpgrade git-instawebUpgrade git-emailUpgrade perl-Git-SVNUpgrade git-daemonUpgrade git-gui | Apr 27, 2020 | Jan 24, 2020 |
| Amazon_linux | — | Upgrade git | Dec 12, 2019 | Dec 9, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 24, 2020 |
| Centos_linux | — | Upgrade git-debugsourceUpgrade git-core-debuginfoUpgrade perl-Git-SVNUpgrade git-coreUpgrade git-instawebUpgrade git-guiUpgrade git-subtreeUpgrade git-svn-debuginfoUpgrade gitkUpgrade gitwebUpgrade git-daemon-debuginfoUpgrade git-allUpgrade git-debuginfoUpgrade gitUpgrade git-svnUpgrade perl-GitUpgrade git-daemonUpgrade git-core-docUpgrade git-email | Dec 23, 2019 | Dec 19, 2019 |
| Debian | — | Upgrade git | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | Feb 24, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-core-docUpgrade gitUpgrade git-core | Feb 26, 2020 | Jan 24, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Dec 10, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Jan 24, 2020 |
| Oracle_linux | — | Upgrade gitkUpgrade git-coreUpgrade git-guiUpgrade perl-GitUpgrade git-instawebUpgrade git-allUpgrade perl-Git-SVNUpgrade git-daemonUpgrade git-emailUpgrade git-core-docUpgrade git-subtreeUpgrade gitwebUpgrade gitUpgrade git-svn | Oct 5, 2022 | Dec 10, 2019 |
| Redhat_linux | — | Upgrade perl-Git-SVNUpgrade git-svn-debuginfoUpgrade git-debugsourceUpgrade git-subtreeUpgrade git-coreUpgrade git-core-docUpgrade git-daemon-debuginfoUpgrade git-allUpgrade git-svnUpgrade gitUpgrade gitwebUpgrade git-emailUpgrade git-instawebUpgrade git-guiNo solution existsUpgrade gitkUpgrade git-core-debuginfoUpgrade git-debuginfoUpgrade perl-GitUpgrade git-daemon | Dec 20, 2019 | Dec 19, 2019 |
| Suse | — | Upgrade libgit2-28Upgrade git-credential-gnome-keyringUpgrade git-svnUpgrade git-coreUpgrade git-guiUpgrade git-daemonUpgrade git-emailUpgrade git-p4Upgrade perl-Authen-SASLUpgrade git-archUpgrade git-cvsUpgrade gitkUpgrade libgit2-develUpgrade gitUpgrade git-docUpgrade git-webUpgrade git-credential-libsecretUpgrade perl-Net-SMTP-SSL | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Jan 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub