CVE-2018-11235

Impact:
Important
Public Date:
2018-05-30
CWE:
CWE-20
Bugzilla:
1583862: CVE-2018-11235 git: arbitrary code execution when recursively cloning a malicious repository

The MITRE CVE dictionary describes this issue as:

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.

Find out more about CVE-2018-11235 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Openshift Container Platform (OCP) does not ship the vulnerable code. However OCP uses the 'git' binary from Red Hat Enterprise Linux (RHEL), or Red Hat Atomic Host (Atomic Host). OCP users will need to upgrade to the latest version of OCP which updates the 'git' binary once it becomes available.

This issue did not affect the versions of git as shipped with Red Hat Enterprise Linux 6 as they did not include the vulnerable code.

CVSS v3 metrics

CVSS3 Base Score 8.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (git) RHSA-2018:1957 2018-06-21
Red Hat Software Collections for Red Hat Enterprise Linux 7 (rh-git29-git) RHSA-2018:2147 2018-07-10
Red Hat Software Collections for Red Hat Enterprise Linux 6 (rh-git29-git) RHSA-2018:2147 2018-07-10

Affected Packages State

Platform Package State
Red Hat OpenShift Enterprise 3 source-to-image Not affected
Red Hat OpenShift Enterprise 3 atomic-openshift Not affected
Red Hat Mobile Application Platform On-Premise 4 fh-scm Not affected
Red Hat JBoss Fuse Service Works 6 jgit Not affected
Red Hat JBoss Fuse 7 camel Not affected
Red Hat JBoss Fuse 6 camel Not affected
Red Hat JBoss Data Virtualization 6 jgit Not affected
Red Hat JBoss BRMS 6 jgit Not affected
Red Hat JBoss A-MQ 6 jgit Not affected
Red Hat Enterprise Linux 6 git Not affected

External References

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.