Back to Database
Status published
High
CVE-2014-9938
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names...
Vulnerability Description
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9938
Credits & Attribution
No credits recorded in the NVD database.
References
More from git-scm
View All →CVE-2022-24975
The --mirror documentation for Git through 2.35.1 does not mention...
High
7.5
CVE-2021-40330
git_connect_git in connect.c in Git before 2.30.1 allows a repository...
High
7.5
CVE-2019-19604
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x...
High
7.8
CVE-2018-19486
Git before 2.19.2 on Linux and UNIX executes commands from...
Critical
9.8
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x...
Critical
9.8
Affected Vendor
git-scm
View all reports →Affected Software
git
Vulnerable Versions:
0
Timeline
Official Publish:
March 20th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.