CVE-2019-1348Improper Input Validation in GIT

Severity
3.3LOWNVD
EPSS
0.1%
top 84.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 24

Description

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVDgit-scm/git2.14.02.14.6+10
Debiangit/git< 1:2.24.0-2+3
NVDopensuse/leap15.1
CVEListV5microsoft_corporation/gitBefore 2.24.1, 2.23.1, 2.22.2, 2.21.1, 2.20.2, 2.19.3, 2.18.2, 2.17.3, 2.16.6, 2.15.4, 2.14.6

🔴Vulnerability Details

2
OSV
CVE-2019-1348: An issue was found in Git before v22020-01-24
CVEList
CVE-2019-1348: An issue was found in Git before v22020-01-24

📋Vendor Advisories

4
Red Hat
git: Arbitrary path overwriting via export-marks in-stream command feature2019-12-10
Ubuntu
Git vulnerabilities2019-12-10
Apple
CVE-2019-1348: Xcode 11.22019-10-31
Debian
CVE-2019-1348: git - An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2...2019

💬Community

2
Bugzilla
CVE-2019-1348 git: Arbitrary path overwriting via export-marks command option [fedora-all]2019-12-11
Bugzilla
CVE-2019-1348 git: Arbitrary path overwriting via export-marks in-stream command feature2019-12-10