This site requires JavaScript to be enabled to function correctly, please enable it.
 
  
    
    
    
    
    Summary: 
    CVE-2019-1350 git: Incorrect quoting of command-line arguments allowed remote code execution during a recursive clone 
   
    
      Product: 
      
          [Other] Security Response
       
Reporter: 
      Pedro Sampaio <psampaio> 
     
    
    Component: 
    vulnerability Assignee: 
      Red Hat Product Security <security-response-team> 
   
    
    
      Status: 
      CLOSED
        NOTABUG
       
QA Contact: 
       
    
      Severity: 
      high
       
Docs Contact: 
       
    
      Priority: 
      high
       
  
        
     
    
    Version: 
    unspecified CC: 
      amahdal, besser82, c.david86, chrisw, hhorak, jorton, opohorel, pcahyna, pstodulk, sebastian.kisela, tmz
    
    
    Target Milestone: 
    --- Keywords: 
      Security 
   
    
    Target Release: 
    ---   
        
   
    
    Hardware: 
    All   
        
   
    OS: 
    Linux   
        
   
    Whiteboard: 
     
        
        
        
  Fixed In Version: 
  
  
 
  git 2.24.1, git 2.23.1, git 2.22.2, git 2.21.1, git 2.20.2, git 2.19.3, git 2.18.2, git 2.17.3, git 2.16.6, git 2.15.4, git 2.14.6
 
        
        
        
        
  Doc Type: 
  
   
  If docs needed, set a value
 
        
  Doc Text: 
  
   
  
      
 
        
        
        
        
  Story Points: 
  
  
 
  ---
 
        
  Clone Of: 
  
  
 
  
 
        
        
        
        
  Environment: 
  
  
 
  
      
 
        
  Last Closed: 
  
  
 
  2019-12-17 10:47:59 UTC
    
 
        
        
        
        
  Type: 
  
  
 
  ---
 
        
  Regression: 
  
  
 
  ---
 
        
        
        
        
  Mount Type: 
  
  
 
  ---
 
        
  Documentation: 
  
  
 
  ---
 
        
        
        
        
  CRM: 
  
  
 
  
 
        
  Verified Versions: 
  
   
  
 
        
        
        
        
  Category: 
  
  
 
  ---
 
        
  oVirt Team: 
  
  
 
  ---
 
        
        
        
        
  RHEL 7.3 requirements from Atomic Host: 
  
  
 
  
 
        
  Cloudforms Team: 
  
  
 
  ---
 
        
        
        
        
  Target Upstream Version: 
  
   
  
 
        
  Embargoed: 
  
  
 
  
 
        
    
    Bug Depends On: 
    1781959 
      
        
   
    Bug Blocks: 
    1781145