A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2Upgrade gitUpgrade libgit2-1.0Upgrade libgit2-1.1 | Aug 22, 2024 | Jan 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-subtreeUpgrade git-allUpgrade gitUpgrade gitwebUpgrade git-cvsUpgrade git-svnUpgrade perl-Git-SVNUpgrade git-coreUpgrade git-daemonUpgrade git-emailUpgrade git-core-docUpgrade gitkUpgrade git-p4Upgrade git-guiUpgrade git-instawebUpgrade git-debuginfoUpgrade perl-Git | Apr 27, 2020 | Jan 24, 2020 |
| Amazon_linux | — | Upgrade git | Dec 12, 2019 | Dec 9, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 24, 2020 |
| Centos_linux | — | Upgrade git-coreUpgrade git-core-debuginfoUpgrade git-svn-debuginfoUpgrade gitkUpgrade git-subtreeUpgrade git-guiUpgrade git-debugsourceUpgrade git-daemon-debuginfoUpgrade perl-Git-SVNUpgrade git-instawebUpgrade gitwebUpgrade git-emailUpgrade git-core-docUpgrade git-daemonUpgrade git-debuginfoUpgrade gitUpgrade git-svnUpgrade perl-GitUpgrade git-all | Dec 23, 2019 | Dec 19, 2019 |
| Debian | — | Upgrade git | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-core-docUpgrade git-coreUpgrade git | Feb 24, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Feb 26, 2020 | Jan 24, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Dec 10, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Jan 24, 2020 |
| Oracle_linux | — | Upgrade git-svnUpgrade gitUpgrade gitwebUpgrade git-subtreeUpgrade git-coreUpgrade git-guiUpgrade git-daemonUpgrade gitkUpgrade perl-GitUpgrade git-allUpgrade perl-Git-SVNUpgrade git-core-docUpgrade git-emailUpgrade git-instaweb | Oct 5, 2022 | Dec 10, 2019 |
| Redhat_linux | — | Upgrade git-svn-debuginfoUpgrade git-core-docUpgrade git-debugsourceUpgrade git-subtreeUpgrade git-daemon-debuginfoUpgrade gitwebUpgrade git-svnUpgrade git-coreUpgrade perl-Git-SVNUpgrade gitUpgrade git-allUpgrade gitkUpgrade git-core-debuginfoNo solution existsUpgrade git-daemonUpgrade git-guiUpgrade git-emailUpgrade perl-GitUpgrade git-debuginfoUpgrade git-instaweb | Dec 20, 2019 | Dec 19, 2019 |
| Suse | — | Upgrade perl-Authen-SASLUpgrade git-svnUpgrade git-daemonUpgrade git-credential-gnome-keyringUpgrade git-coreUpgrade git-emailUpgrade libgit2-28Upgrade git-p4Upgrade git-guiUpgrade git-webUpgrade git-archUpgrade git-cvsUpgrade gitkUpgrade git-credential-libsecretUpgrade libgit2-develUpgrade gitUpgrade perl-Net-SMTP-SSLUpgrade git-doc | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Jan 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub