CVE-2019-1348: Input Validation
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
Other sources
Git. An input validation issue was addressed.
The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
References:
https://kernel.googlesource.com/pub/scm/git/git/+/refs/tags/v2.24.1/Documentation/RelNotes/2.14.6.txt
— Red Hat
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-1348?
The severity of CVE-2019-1348 is medium with a severity value of 3.3.
What is the affected software of CVE-2019-1348?
The affected software of CVE-2019-1348 includes Git versions before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6.
How can I fix CVE-2019-1348?
To fix CVE-2019-1348, update Git to version 2.24.1 or later.
Where can I find more information about CVE-2019-1348?
You can find more information about CVE-2019-1348 at the following references: [1] [2] [3].
What is the CWE ID of CVE-2019-1348?
The CWE ID of CVE-2019-1348 is 20.