Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 22, 2024 | Dec 10, 2019 |
| Amazon Linux Ami 2 | — | Upgrade perl-GitUpgrade gitUpgrade git-core-docUpgrade gitkUpgrade git-emailUpgrade git-p4Upgrade git-debuginfoUpgrade git-allUpgrade git-cvsUpgrade gitwebUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-daemonUpgrade git-coreUpgrade git-instawebUpgrade git-guiUpgrade git-subtree | Apr 27, 2020 | Dec 11, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 10, 2019 |
| Debian | — | Upgrade git | Jul 30, 2024 | Dec 11, 2019 |
| Freebsd | — | Upgrade gitlab-ce | Dec 11, 2019 | Dec 10, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-core-docUpgrade git-coreUpgrade git | Feb 24, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | Feb 26, 2020 | Dec 11, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Dec 11, 2019 |
| Suse | — | Upgrade git-emailUpgrade git-guiUpgrade perl-Authen-SASLUpgrade gitkUpgrade git-credential-gnome-keyringUpgrade git-p4Upgrade git-cvsUpgrade git-archUpgrade git-svnUpgrade gitUpgrade git-docUpgrade git-daemonUpgrade git-coreUpgrade git-credential-libsecretUpgrade git-webUpgrade perl-Net-SMTP-SSL | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub