Back to search
CVE-2019-1387
Published: Dec 18, 2019
Modified: Nov 4, 2025
PUBLISHED
Description
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.
| Vendor | Product | Versions |
|---|---|---|
Microsoft Corporation | Git | affected Before v2.24.1affected Before v2.23.1affected Before v2.22.2affected Before v2.21.1affected Before v2.20.2+6 more versions |
References
RHSA-2019:4356
vendor-advisory
RHSA-2020:0002
vendor-advisory
FEDORA-2019-1cec196e20
vendor-advisory
RHSA-2020:0124
vendor-advisory
openSUSE-SU-2020:0123
vendor-advisory
RHSA-2020:0228
vendor-advisory
GLSA-202003-30
vendor-advisory
GLSA-202003-42
vendor-advisory
openSUSE-SU-2020:0598
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now