A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gitUpgrade libgit2Upgrade libgit2-1.0Upgrade libgit2-1.1 | Aug 22, 2024 | Jan 24, 2020 |
| Amazon Linux Ami 2 | — | Upgrade perl-Git-SVNUpgrade git-core-docUpgrade git-instawebUpgrade git-guiUpgrade git-daemonUpgrade git-p4Upgrade perl-GitUpgrade git-coreUpgrade gitkUpgrade git-emailUpgrade git-debuginfoUpgrade git-svnUpgrade git-allUpgrade git-subtreeUpgrade gitwebUpgrade git-cvsUpgrade git | Apr 27, 2020 | Jan 24, 2020 |
| Amazon_linux | — | Upgrade git | Dec 12, 2019 | Dec 9, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 24, 2020 |
| Centos_linux | — | Upgrade git-daemon-debuginfoUpgrade perl-Git-SVNUpgrade gitkUpgrade git-guiUpgrade gitwebUpgrade git-svn-debuginfoUpgrade git-subtreeUpgrade git-coreUpgrade git-core-debuginfoUpgrade git-debugsourceUpgrade git-instawebUpgrade git-svnUpgrade git-core-docUpgrade git-debuginfoUpgrade git-emailUpgrade git-daemonUpgrade git-allUpgrade perl-GitUpgrade git | Dec 23, 2019 | Dec 19, 2019 |
| Debian | — | Upgrade git | Dec 12, 2019 | Dec 12, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-core-docUpgrade git-coreUpgrade git | Feb 24, 2020 | Jan 24, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-core-docUpgrade gitUpgrade git-core | Feb 26, 2020 | Jan 24, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Dec 10, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Jan 24, 2020 |
| Oracle_linux | — | Upgrade git-subtreeUpgrade git-svnUpgrade gitUpgrade gitwebUpgrade perl-GitUpgrade git-core-docUpgrade gitkUpgrade perl-Git-SVNUpgrade git-instawebUpgrade git-coreUpgrade git-allUpgrade git-daemonUpgrade git-emailUpgrade git-gui | Oct 5, 2022 | Dec 10, 2019 |
| Redhat_linux | — | No solution existsUpgrade gitkUpgrade git-instawebUpgrade git-debuginfoUpgrade git-guiUpgrade git-core-debuginfoUpgrade git-emailUpgrade perl-GitUpgrade git-daemonUpgrade git-svnUpgrade git-subtreeUpgrade git-debugsourceUpgrade git-coreUpgrade git-svn-debuginfoUpgrade gitUpgrade gitwebUpgrade git-daemon-debuginfoUpgrade git-allUpgrade perl-Git-SVNUpgrade git-core-doc | Dec 20, 2019 | Dec 19, 2019 |
| Suse | — | Upgrade git-cvsUpgrade libgit2-develUpgrade gitUpgrade perl-Net-SMTP-SSLUpgrade git-webUpgrade gitkUpgrade git-archUpgrade git-credential-libsecretUpgrade git-docUpgrade git-p4Upgrade git-guiUpgrade git-coreUpgrade perl-Authen-SASLUpgrade libgit2-28Upgrade git-daemonUpgrade git-emailUpgrade git-svnUpgrade git-credential-gnome-keyring | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Jan 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub