A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2-1.0Upgrade libgit2-1.1Upgrade gitUpgrade libgit2 | Aug 22, 2024 | Jan 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-svnUpgrade git-subtreeUpgrade gitUpgrade git-allUpgrade gitwebUpgrade git-cvsUpgrade gitkUpgrade git-coreUpgrade git-instawebUpgrade git-debuginfoUpgrade perl-GitUpgrade perl-Git-SVNUpgrade git-emailUpgrade git-core-docUpgrade git-daemonUpgrade git-p4Upgrade git-gui | Apr 27, 2020 | Jan 24, 2020 |
| Amazon_linux | — | Upgrade git | Dec 12, 2019 | Dec 9, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 24, 2020 |
| Centos_linux | — | Upgrade perl-Git-SVNUpgrade git-daemon-debuginfoUpgrade git-svn-debuginfoUpgrade git-instawebUpgrade git-guiUpgrade git-coreUpgrade git-subtreeUpgrade gitwebUpgrade git-core-debuginfoUpgrade gitkUpgrade git-debugsourceUpgrade gitUpgrade git-svnUpgrade git-core-docUpgrade git-emailUpgrade git-daemonUpgrade git-allUpgrade perl-GitUpgrade git-debuginfo | Dec 23, 2019 | Dec 19, 2019 |
| Debian | — | Upgrade git | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-coreUpgrade git-core-doc | Feb 24, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | Feb 26, 2020 | Jan 24, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Dec 10, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Jan 24, 2020 |
| Oracle_linux | — | Upgrade git-svnUpgrade gitwebUpgrade git-subtreeUpgrade gitUpgrade git-core-docUpgrade gitkUpgrade git-instawebUpgrade perl-Git-SVNUpgrade perl-GitUpgrade git-allUpgrade git-coreUpgrade git-guiUpgrade git-daemonUpgrade git-email | Oct 5, 2022 | Dec 10, 2019 |
| Redhat_linux | — | Upgrade git-debugsourceUpgrade gitwebUpgrade gitUpgrade git-svnUpgrade git-core-docUpgrade git-subtreeUpgrade git-coreUpgrade git-svn-debuginfoUpgrade perl-Git-SVNUpgrade git-allUpgrade git-daemon-debuginfoNo solution existsUpgrade git-guiUpgrade git-core-debuginfoUpgrade git-debuginfoUpgrade git-instawebUpgrade perl-GitUpgrade git-daemonUpgrade gitkUpgrade git-email | Dec 20, 2019 | Dec 19, 2019 |
| Suse | — | Upgrade git-docUpgrade git-webUpgrade git-cvsUpgrade git-archUpgrade libgit2-develUpgrade git-credential-libsecretUpgrade gitUpgrade perl-Net-SMTP-SSLUpgrade gitkUpgrade git-guiUpgrade git-daemonUpgrade git-credential-gnome-keyringUpgrade libgit2-28Upgrade perl-Authen-SASLUpgrade git-p4Upgrade git-coreUpgrade git-svnUpgrade git-email | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Jan 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub