A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libgit2Upgrade gitUpgrade libgit2-1.1Upgrade libgit2-1.0 | Aug 22, 2024 | Jan 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-svnUpgrade git-cvsUpgrade git-subtreeUpgrade gitUpgrade git-allUpgrade gitwebUpgrade gitkUpgrade git-emailUpgrade perl-Git-SVNUpgrade git-core-docUpgrade git-p4Upgrade git-guiUpgrade git-coreUpgrade git-daemonUpgrade git-debuginfoUpgrade perl-GitUpgrade git-instaweb | Apr 27, 2020 | Jan 24, 2020 |
| Amazon_linux | — | Upgrade git | Dec 12, 2019 | Dec 9, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 24, 2020 |
| Centos_linux | — | Upgrade git-core-debuginfoUpgrade git-svn-debuginfoUpgrade git-coreUpgrade git-debugsourceUpgrade gitwebUpgrade git-subtreeUpgrade git-guiUpgrade gitkUpgrade git-daemon-debuginfoUpgrade git-instawebUpgrade perl-Git-SVNUpgrade git-debuginfoUpgrade git-daemonUpgrade git-emailUpgrade gitUpgrade git-core-docUpgrade perl-GitUpgrade git-svnUpgrade git-all | Dec 23, 2019 | Dec 19, 2019 |
| Debian | — | Upgrade git | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Feb 24, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Feb 26, 2020 | Jan 24, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Dec 10, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Jan 24, 2020 |
| Oracle_linux | — | Upgrade gitUpgrade git-svnUpgrade gitwebUpgrade git-subtreeUpgrade git-allUpgrade perl-Git-SVNUpgrade git-daemonUpgrade perl-GitUpgrade git-core-docUpgrade git-instawebUpgrade gitkUpgrade git-guiUpgrade git-emailUpgrade git-core | Oct 5, 2022 | Dec 10, 2019 |
| Redhat_linux | — | Upgrade git-core-debuginfoNo solution existsUpgrade gitkUpgrade git-daemonUpgrade git-guiUpgrade git-instawebUpgrade perl-GitUpgrade git-debuginfoUpgrade git-emailUpgrade gitUpgrade git-subtreeUpgrade git-svn-debuginfoUpgrade git-coreUpgrade gitwebUpgrade git-debugsourceUpgrade git-core-docUpgrade git-daemon-debuginfoUpgrade perl-Git-SVNUpgrade git-allUpgrade git-svn | Dec 20, 2019 | Dec 19, 2019 |
| Suse | — | Upgrade git-credential-gnome-keyringUpgrade git-p4Upgrade libgit2-28Upgrade git-guiUpgrade git-emailUpgrade git-svnUpgrade perl-Authen-SASLUpgrade git-daemonUpgrade git-coreUpgrade git-archUpgrade gitUpgrade perl-Net-SMTP-SSLUpgrade git-webUpgrade git-cvsUpgrade libgit2-develUpgrade gitkUpgrade git-credential-libsecretUpgrade git-doc | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Jan 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub