Endpoint Vulnerability

CVE-2019-19604git: Recursive clone followed by a submodule update could execute code contained within repository without the user explicitly consent

Description

A security bypass was discovered in git, which allows arbitrary commands to be executed during the update of git submodules. A remote attacker may trick a victim user into cloning a malicious repository that initially looks fine, allowing access to bypass the security mechanisms that prevent the execution of arbitrary commands during the submodule initialization. After following an update of the repository and the submodules done by the victim user, vulnerable versions of git may use the update setting in the .gitmodules file and execute arbitrary commands.

Affected Products

git

References

CVE-2019-19604,