OS Command Injection in Git - CVE-2019-19604
Published: December 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to a "git submodule update" operation can run commands found in the ".gitmodules" file of a malicious repository. A remote unauthenticated attacker can execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Arch Linux
Opensuse
Fedora
git (Ubuntu package)
git (Debian package)
git (Alpine package)
git
Pivotal Concourse
How to mitigate CVE-2019-19604
git (Ubuntu package) - addressed in versions 1:2.7.4-0ubuntu1.7, 1:2.17.1-1ubuntu0.5, 1:2.20.1-2ubuntu1.19.04.1, 1:2.20.1-2ubuntu1.19.10.1
git (Debian package) - addressed in versions 1:2.11.0-3+deb9u5, 1:2.20.1-2+deb10u1
git (Alpine package) - update to 2.22.2-r0
Pivotal Concourse - addressed in versions 5.2.6, 5.5.7
git - addressed in versions 2.21.1-1.fc30, 2.24.1-1.fc31
External References
Related Security Bulletins
- Debian update for git
- Ubuntu update for Git
- Multiple vulnerabilities in Git
- Arch Linux update for git
- Pivotal Concourse update for Git
- OpenSUSE Linux update for git
- Gentoo update for Git
- OpenSUSE Linux update for git
- OS Command Injection in git (Alpine package)
- Fedora 30 update for git
- Fedora 31 update for git