Improper Input Validation
Affecting git package, versions <1:2.11.0-3+deb9u5
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.
References
CVSS Score
8.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2019-1387
- Snyk ID
- SNYK-DEBIAN9-GIT-537154
- Disclosed
- 18 Dec, 2019
- Published
- 10 Dec, 2019