CVE-2019-1387 - CVE House
Back to Database
Status published High CVE-2019-1387

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2,...

Vulnerability Description

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-1387

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Microsoft Corporation

View all reports →

Affected Software

Git
Vulnerable Versions:
Before v2.24.1, Before v2.23.1, Before v2.22.2, Before v2.21.1, Before v2.20.2, Before v2.19.3, Before v2.18.2, Before v2.17.3, Before v2.16.6, Before v2.15.4, Before v2.14.6

Timeline

Official Publish: December 18th, 2019
Last Modified: November 4th, 2025
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.