CVE-2018-11235
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 48.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 48.75% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation · git-scm/git · gitforwindows/git
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html
- http://www.securityfocus.com/bid/104345Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040991Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1957Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2147Third Party Advisory
- https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/Patch, Technical Description, Vendor Advisory
- https://marc.info/?l=git&m=152761328506724&w=2Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/201805-13Third Party Advisory
- https://usn.ubuntu.com/3671-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4212Third Party Advisory
- https://www.exploit-db.com/exploits/44822/Exploit, Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html
- http://www.securityfocus.com/bid/104345Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040991Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1957Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2147Third Party Advisory
- https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/Patch, Technical Description, Vendor Advisory
- https://marc.info/?l=git&m=152761328506724&w=2Release Notes, Third Party Advisory
- https://security.gentoo.org/glsa/201805-13Third Party Advisory
- https://usn.ubuntu.com/3671-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4212Third Party Advisory
- https://www.exploit-db.com/exploits/44822/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.