CVE-2019-1348: Git-Scm Git

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

Affected products

  • Git-Scm Git: from 2.14.0, before 2.14.6 (fixed in 2.14.6); from 2.15.0, before 2.15.4 (fixed in 2.15.4); from 2.16.0, before 2.16.6 (fixed in 2.16.6); from 2.17.0, before 2.17.3 (fixed in 2.17.3); from 2.18.0, before 2.18.2 (fixed in 2.18.2); from 2.19.0, before 2.19.3 (fixed in 2.19.3); …
  • Opensuse Leap: version 15.1 only

Published 2020-01-24. Last modified 2026-06-17.