CVE-2019-1348
low-risk
Published 2020-01-24
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.3/10
Low
LOCAL
/ LOW complexity
References (16)
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0228
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00056.html
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0228
20
/ 100
low-risk
Severity
13/34 · Low
Exploitability
0/34 · Minimal
Exposure
7/34 · Low