A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Aug 22, 2024 | Oct 4, 2017 |
| Amazon_linux | — | Upgrade git | Dec 20, 2017 | Aug 31, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 4, 2017 |
| Centos_linux | — | Upgrade git-svnUpgrade git-daemonUpgrade git-cvsUpgrade perl-Git-SVNUpgrade git-guiUpgrade git-emailUpgrade git-bzrUpgrade emacs-gitUpgrade git-hgUpgrade gitUpgrade git-debuginfoUpgrade git-p4Upgrade gitkUpgrade emacs-git-elUpgrade git-allUpgrade perl-GitUpgrade gitweb | Aug 28, 2019 | Oct 5, 2017 |
| Debian | — | Upgrade git | Dec 4, 2017 | Aug 10, 2017 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Oct 30, 2017 | Oct 4, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade git | Nov 30, 2017 | Oct 4, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Nov 30, 2017 | Oct 4, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade developer/versioning/cvs to version 1.12.13-0.175.3.24.0.3.0 on Solaris 11.3 | Sep 19, 2017 | Sep 19, 2017 |
| Oracle_linux | — | Upgrade perl-Git-SVNUpgrade git-guiUpgrade git-svnUpgrade gitwebUpgrade git-daemonUpgrade gitkUpgrade git-bzrUpgrade git-hgUpgrade emacs-gitUpgrade gitUpgrade git-p4Upgrade emacs-git-elUpgrade git-cvsUpgrade perl-GitUpgrade git-allUpgrade git-email | Dec 20, 2017 | Aug 10, 2017 |
| Redhat_linux | — | Upgrade git-debuginfoUpgrade git-emailUpgrade git-bzrUpgrade git-daemonUpgrade git-guiUpgrade git-hgUpgrade git-svnUpgrade git-cvsUpgrade perl-Git-SVNUpgrade emacs-gitUpgrade git-allUpgrade emacs-git-elUpgrade git-p4Upgrade gitUpgrade perl-GitUpgrade gitkUpgrade gitweb | Jan 17, 2018 | Aug 16, 2017 |
| Suse | — | Upgrade git-docUpgrade git-webUpgrade gitUpgrade git-svnUpgrade git-coreUpgrade git-archUpgrade git-daemonUpgrade git-emailUpgrade gitkUpgrade git-cvsUpgrade git-gui | Jan 26, 2018 | Aug 21, 2017 |
| Ubuntu | — | Upgrade git | Dec 20, 2017 | Aug 11, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2025 | Oct 4, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub