Multiple Git vulnerabilities in 2.24 and older
Learn more about the security vulnerabilities in Git 2.24 and older.
data:image/s3,"s3://crabby-images/08ef2/08ef211f000d8cab17a933e200bf14ea46e62539" alt=""
Today, the Git project released a series of security patches to address multiple security vulnerabilities in versions 2.24 and older.
These updates are highly recommended for all Git users, but they’re especially critical if you use Git on Windows[1]. If you clone untrusted repositories, there is no workaround that avoids the risk of any vulnerabilities disclosed in this post, except for updating.
If you use Git on another operating system, this update is still highly recommended. However, if you can’t update immediately, here are some things you can do to reduce your risk:
- Avoid running
git clone --recurse-submodules
andgit submodule update
with untrusted repositories. - Avoid running
git fast-import
on untrusted input streams. It’s still safe to use remote helpers that usegit fast-import
on the backend (such asgit-remote-hg
,git-p4
). - Avoid cloning untrusted repositories into NTFS mounts on any platform.
The new releases contain partial support for rejecting pushes that exploit these vulnerabilities, but some cases remain uncovered. It’s important to update, and not rely on hosting providers to block all exploits.
If you use GitHub Enterprise Server, these fixes will be included in the next patch release for all supported versions.
[1]: CVEs CVE-2019-1350, CVE-2019-1351, CVE-2019-1352, CVE-2019-1353, and, CVE-2019-1354 are Windows-specific vulnerabilities that can lead to remote code execution when cloning an untrusted repository. They’re patched only in today’s security releases. CVE-2019-1352 can affect non-Windows users, but only if you mount an NTFS volume.
Tags:
Written by
Related posts
data:image/s3,"s3://crabby-images/2c149/2c1494a8bc228f46152d18f5b8597b6d3bb4d36d" alt=""
Support the open source projects you love this Valentine’s Day
Show your appreciation to the open source projects you love. You can help provide much-needed support to the critical but often underfunded projects that keep your infrastructure running smoothly. And remember—every day is a perfect day to support open source! 💖
data:image/s3,"s3://crabby-images/b5149/b514975f080dd9da5012ef176070d07a65df5504" alt=""
5 tips for promoting your open source project
Three open source experts offer their advice on sharing open source projects with the world.
data:image/s3,"s3://crabby-images/7f8c7/7f8c7de03b02f5127a67a4860e1167e99347b734" alt=""
4 steps to building a natural language search tool
Empowering humanitarian action with open source: A natural language search tool for UN Resolutions.