Back

LOW

git: Arbitrary path overwriting via export-marks in-stream command feature

Published Jan 24, 2020

Description

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

Affected products

Remediation

Red Hat mitigation

Avoid running `git fast-import` on untrusted input.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Jan 24, 2020
Updated Aug 4, 2024
Reserved Nov 26, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 10, 2019