Use of Incorrectly-Resolved Name or Reference
Affecting git package, versions <2.15.4-r0
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Use of Incorrectly-Resolved Name or Reference. A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
Remediation
Upgrade git
to version or higher.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityHigh
-
AvailabilityNone
- CVE
- CVE-2019-1351
- CWE
- CWE-706
- Snyk ID
- SNYK-ALPINE37-GIT-1015579
- Disclosed
- 24 Jan, 2020
- Published
- 10 Dec, 2019