Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 22, 2024 | Dec 10, 2019 |
| Amazon Linux Ami 2 | — | Upgrade git-coreUpgrade git-guiUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-daemonUpgrade git-instawebUpgrade git-subtreeUpgrade gitwebUpgrade git-debuginfoUpgrade gitkUpgrade git-p4Upgrade perl-GitUpgrade gitUpgrade git-core-docUpgrade git-allUpgrade git-emailUpgrade git-cvs | Apr 27, 2020 | Dec 11, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 10, 2019 |
| Debian | — | Upgrade git | Jul 30, 2024 | Dec 11, 2019 |
| Freebsd | — | Upgrade gitlab-ce | Dec 11, 2019 | Dec 10, 2019 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Mar 16, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Feb 24, 2020 | Dec 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Feb 26, 2020 | Dec 11, 2019 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.3-11.4.19.0.1.1.0 on Solaris 11.4 | Jan 19, 2021 | Dec 11, 2019 |
| Suse | — | Upgrade git-docUpgrade gitUpgrade git-credential-libsecretUpgrade git-svnUpgrade perl-Net-SMTP-SSLUpgrade git-coreUpgrade git-webUpgrade git-daemonUpgrade perl-Authen-SASLUpgrade git-cvsUpgrade git-archUpgrade git-emailUpgrade gitkUpgrade git-guiUpgrade git-p4Upgrade git-credential-gnome-keyring | Dec 17, 2019 | Dec 10, 2019 |
| Ubuntu | — | Upgrade git | Dec 11, 2019 | Dec 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub