Back

HIGH

git: Remote code execution in recursive clones with nested submodules

Published Dec 18, 2019

Description

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 as they did not use submodules names to construct git metadata paths.

Red Hat mitigation

Avoid running `git clone --recurse-submodules` and `git submodule update` with untrusted repositories.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Dec 18, 2019
Updated Nov 4, 2025
Reserved Nov 26, 2018
CISA Vulnrichment
Updated Jul 19, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 10, 2019