cbcvebase.

Debian Git vulnerabilities

50 known vulnerabilities affecting debian/git.

Total CVEs
50
CISA KEV
1
actively exploited
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH19MEDIUM8LOW13

Vulnerabilities

Page 2 of 3
CVE-2019-1387P3HIGHCVSS 8.8fixed in git 1:2.24.0-2 (bookworm)2019
CVE-2019-1387 [HIGH] CVE-2019-1387: git - An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2... An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones. Scope: local bookworm: resolved (fixed in 1:
debian
CVE-2020-5260P3CRITICALCVSS 9.3fixed in git 1:2.26.1-1 (bookworm)2020
CVE-2020-5260 [CRITICAL] CVE-2020-5260: git - Affected versions of Git have a vulnerability whereby Git can be tricked into se... Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can inject uninten
debian
CVE-2025-48385P3HIGHCVSS 8.6fixed in git 1:2.39.5-0+deb12u3 (bookworm)2025
CVE-2025-48385 [HIGH] CVE-2025-48385: git - Git is a fast, scalable, distributed revision control system with an unusually r... Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the clone to a CDN. The Git client does not perform suffic
debian
CVE-2018-19486P3CRITICALCVSS 9.8fixed in git 1:2.19.2-1 (bookworm)2018
CVE-2018-19486 [CRITICAL] CVE-2018-19486: git - Git before 2.19.2 on Linux and UNIX executes commands from the current working d... Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017. Scope: local bookworm: resolved (fixed in 1:2.19.2-1) bullseye: resolved (fixed in 1:2.19.2-1) forky: r
debian
CVE-2020-11008P3MEDIUMCVSS 4.0fixed in git 1:2.26.2-1 (bookworm)2020
CVE-2020-11008 [MEDIUM] CVE-2020-11008: git - Affected versions of Git have a vulnerability whereby Git can be tricked into se... Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credentia
debian
CVE-2019-1353P3CRITICALCVSS 9.8fixed in git 1:2.24.0-2 (bookworm)2019
CVE-2019-1353 [CRITICAL] CVE-2019-1353: git - An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2... An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active. Scope: local bookworm: resolved (fixed in 1:2.24.0-2)
debian
CVE-2023-29007P3HIGHCVSS 7.0fixed in git 1:2.39.5-0+deb12u1 (bookworm)2023
CVE-2023-29007 [HIGH] CVE-2023-29007: git - Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33... Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary confi
debian
CVE-2010-3906P4MEDIUMCVSS 4.3PoCfixed in git 1:1.7.2.3-2.2 (bookworm)2010
CVE-2010-3906 [MEDIUM] CVE-2010-3906: git - Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows re... Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters. Scope: local bookworm: resolved (fixed in 1:1.7.2.3-2.2) bullseye: resolved (fixed in 1:1.7.2.3-2.2) forky: resolved (fixed in 1:1.7.2.3-2.2) sid: resolved (fixed in 1:1.7.2.3-2.2) trixie: resolved (fi
debian
CVE-2019-19604P3HIGHCVSS 7.8fixed in git 1:2.24.0-2 (bookworm)2019
CVE-2019-19604 [HIGH] CVE-2019-19604: git - Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21... Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository. Scope: local bookworm: resolved (fixed in 1:2.24.0-2) bullseye: resolved (fixed in 1:2.24.0-2) forky:
debian
CVE-2025-27614P3LOWCVSS 8.6fixed in git 1:2.50.1-0.1 (forky)2025
CVE-2025-27614 [HIGH] CVE-2025-27614: git - Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git reposito... Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is r
debian
CVE-2019-1351P3LOWCVSS 7.5fixed in git 1:2.24.0-2 (bookworm)2019
CVE-2019-1351 [HIGH] CVE-2019-1351: git - A tampering vulnerability exists when Git for Visual Studio improperly handles v... A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. Scope: local bookworm: resolved (fixed in 1:2.24.0-2) bullseye: resolved (fixed in 1:2.24.0-2) forky: resolved (fixed in 1:2.24.0-2) sid: resolved (fixed in 1:2.24.0-2) trixie: resolved (fixed in 1:2.24.0-2)
debian
CVE-2025-46835P3HIGHCVSS 8.5fixed in git 1:2.39.5-0+deb12u3 (bookworm)2025
CVE-2025-46835 [HIGH] CVE-2025-46835: git - Git GUI allows you to use the Git source control management tools via a GUI. Whe... Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2
debian
CVE-2024-52006P3CRITICALCVSS 9.3fixed in git 1:2.39.5-0+deb12u2 (bookworm)2024
CVE-2024-52006 [CRITICAL] CVE-2024-52006: git - Git is a fast, scalable, distributed revision control system with an unusually r... Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers. Some ecosystems (most notably, .NET and node.js) interpret single Carriage Return characte
debian
CVE-2024-32004P3HIGHCVSS 8.1fixed in git 1:2.39.5-0+deb12u1 (bookworm)2024
CVE-2024-32004 [HIGH] CVE-2024-32004: git - Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42... Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning re
debian
CVE-2022-29187P3MEDIUMCVSS 6.0fixed in git 1:2.37.2-1 (bookworm)2022
CVE-2022-29187 [MEDIUM] CVE-2022-29187: git - Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36... Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but w
debian
CVE-2014-9938P3HIGHCVSS 8.8fixed in git 1:2.0.0~rc2-1 (bookworm)2014
CVE-2014-9938 [HIGH] CVE-2014-9938: git - contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch na... contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution. Scope: local bookworm: resolved (fixed in 1:2.0.0~rc2-1) bullseye: resolved (fixed in 1:2.0.0~rc2-1) forky: resolved (fixed in 1:2.0.0~rc2-1) sid: resolved (fixed in 1:2.0.0~rc2-1) trixie: resolved (fixed in 1:2.
debian
CVE-2018-11233P3LOWCVSS 7.5fixed in git 1:2.17.1-1 (bookworm)2018
CVE-2018-11233 [HIGH] CVE-2018-11233: git - In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before ... In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory. Scope: local bookworm: resolved (fixed in 1:2.17.1-1) bullseye: resolved (fixed in 1:2.17.1-1) forky: resolved (fixed in 1:2.17.1-1) sid: resolved (fixed in 1:2.17.1-1) trixie
debian
CVE-2021-40330P3HIGHCVSS 7.5fixed in git 1:2.30.1-1 (bookworm)2021
CVE-2021-40330 [HIGH] CVE-2021-40330: git - git_connect_git in connect.c in Git before 2.30.1 allows a repository path to co... git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring. Scope: local bookworm: resolved (fixed in 1:2.30.1-1) bullseye: resolved (fixed in 1:2.30.1-1) forky: resolved (fixed in 1:
debian
CVE-2022-24765P3MEDIUMCVSS 6.0fixed in git 1:2.35.2-1 (bookworm)2022
CVE-2022-24765 [MEDIUM] CVE-2022-24765: git - Git for Windows is a fork of Git containing Windows-specific patches. This vulne... Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly outside a repository while searching for a Git direct
debian
CVE-2023-23946P3MEDIUMCVSS 6.2fixed in git 1:2.39.2-1 (bookworm)2023
CVE-2023-23946 [MEDIUM] CVE-2023-23946: git - Git, a revision control system, is vulnerable to path traversal prior to version... Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6,
debian