Description
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2059-1 | git security update |
Debian DLA |
DLA-3844-1 | git security update |
Debian DLA |
DLA-3867-1 | git security update |
Debian DSA |
DSA-4581-1 | git security update |
EUVD |
EUVD-2019-9944 | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones. |
Ubuntu USN |
USN-4220-1 | Git vulnerabilities |
References
History
Tue, 04 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-11-04T16:09:13.231Z
Reserved: 2018-11-26T00:00:00.000Z
Link: CVE-2019-1387
Updated: 2024-08-04T18:13:30.492Z
Status : Modified
Published: 2019-12-18T21:15:13.820
Modified: 2025-11-04T16:15:42.387
Link: CVE-2019-1387
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN