<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">git-2.33.0-1.3 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10786-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-15T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-15T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-15T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">git-2.33.0-1.3 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the git-2.33.0-1.3 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10786</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2005-4900/</URL>
      <Description>SUSE CVE CVE-2005-4900 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-1000117/</URL>
      <Description>SUSE CVE CVE-2017-1000117 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-14867/</URL>
      <Description>SUSE CVE CVE-2017-14867 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-15298/</URL>
      <Description>SUSE CVE CVE-2017-15298 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-8386/</URL>
      <Description>SUSE CVE CVE-2017-8386 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-11233/</URL>
      <Description>SUSE CVE CVE-2018-11233 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-11235/</URL>
      <Description>SUSE CVE CVE-2018-11235 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-17456/</URL>
      <Description>SUSE CVE CVE-2018-17456 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-19486/</URL>
      <Description>SUSE CVE CVE-2018-19486 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1348/</URL>
      <Description>SUSE CVE CVE-2019-1348 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1349/</URL>
      <Description>SUSE CVE CVE-2019-1349 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1350/</URL>
      <Description>SUSE CVE CVE-2019-1350 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1351/</URL>
      <Description>SUSE CVE CVE-2019-1351 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1352/</URL>
      <Description>SUSE CVE CVE-2019-1352 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1353/</URL>
      <Description>SUSE CVE CVE-2019-1353 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1354/</URL>
      <Description>SUSE CVE CVE-2019-1354 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-1387/</URL>
      <Description>SUSE CVE CVE-2019-1387 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-19604/</URL>
      <Description>SUSE CVE CVE-2019-19604 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-11008/</URL>
      <Description>SUSE CVE CVE-2020-11008 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-5260/</URL>
      <Description>SUSE CVE CVE-2020-5260 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-21300/</URL>
      <Description>SUSE CVE CVE-2021-21300 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="git-2.33.0-1.3">
      <FullProductName ProductID="git-2.33.0-1.3">git-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-arch-2.33.0-1.3">
      <FullProductName ProductID="git-arch-2.33.0-1.3">git-arch-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-core-2.33.0-1.3">
      <FullProductName ProductID="git-core-2.33.0-1.3">git-core-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-credential-gnome-keyring-2.33.0-1.3">
      <FullProductName ProductID="git-credential-gnome-keyring-2.33.0-1.3">git-credential-gnome-keyring-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-credential-libsecret-2.33.0-1.3">
      <FullProductName ProductID="git-credential-libsecret-2.33.0-1.3">git-credential-libsecret-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-cvs-2.33.0-1.3">
      <FullProductName ProductID="git-cvs-2.33.0-1.3">git-cvs-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-daemon-2.33.0-1.3">
      <FullProductName ProductID="git-daemon-2.33.0-1.3">git-daemon-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-doc-2.33.0-1.3">
      <FullProductName ProductID="git-doc-2.33.0-1.3">git-doc-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-email-2.33.0-1.3">
      <FullProductName ProductID="git-email-2.33.0-1.3">git-email-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-gui-2.33.0-1.3">
      <FullProductName ProductID="git-gui-2.33.0-1.3">git-gui-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-p4-2.33.0-1.3">
      <FullProductName ProductID="git-p4-2.33.0-1.3">git-p4-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-svn-2.33.0-1.3">
      <FullProductName ProductID="git-svn-2.33.0-1.3">git-svn-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="git-web-2.33.0-1.3">
      <FullProductName ProductID="git-web-2.33.0-1.3">git-web-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gitk-2.33.0-1.3">
      <FullProductName ProductID="gitk-2.33.0-1.3">gitk-2.33.0-1.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="perl-Git-2.33.0-1.3">
      <FullProductName ProductID="perl-Git-2.33.0-1.3">perl-Git-2.33.0-1.3</FullProductName>
    </Branch>
    <Relationship ProductReference="git-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-2.33.0-1.3">git-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-arch-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-arch-2.33.0-1.3">git-arch-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-core-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-core-2.33.0-1.3">git-core-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-credential-gnome-keyring-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3">git-credential-gnome-keyring-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-credential-libsecret-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3">git-credential-libsecret-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-cvs-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-cvs-2.33.0-1.3">git-cvs-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-daemon-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-daemon-2.33.0-1.3">git-daemon-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-doc-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-doc-2.33.0-1.3">git-doc-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-email-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-email-2.33.0-1.3">git-email-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-gui-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-gui-2.33.0-1.3">git-gui-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-p4-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-p4-2.33.0-1.3">git-p4-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-svn-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-svn-2.33.0-1.3">git-svn-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="git-web-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:git-web-2.33.0-1.3">git-web-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="gitk-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gitk-2.33.0-1.3">gitk-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="perl-Git-2.33.0-1.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:perl-Git-2.33.0-1.3">perl-Git-2.33.0-1.3 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2.  NOTE: this CVE exists to provide a common identifier for referencing this SHA-1 issue; the existence of an identifier is not, by itself, a technology recommendation.</Note>
    </Notes>
    <CVE>CVE-2005-4900</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2005-4900.html</URL>
        <Description>CVE-2005-4900</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1026646</URL>
        <Description>SUSE Bug 1026646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1026936</URL>
        <Description>SUSE Bug 1026936</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1042640</URL>
        <Description>SUSE Bug 1042640</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1150998</URL>
        <Description>SUSE Bug 1150998</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.</Note>
    </Notes>
    <CVE>CVE-2017-1000117</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-1000117.html</URL>
        <Description>CVE-2017-1000117</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1052481</URL>
        <Description>SUSE Bug 1052481</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1052696</URL>
        <Description>SUSE Bug 1052696</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1052932</URL>
        <Description>SUSE Bug 1052932</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1053364</URL>
        <Description>SUSE Bug 1053364</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1053600</URL>
        <Description>SUSE Bug 1053600</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1053919</URL>
        <Description>SUSE Bug 1053919</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1054653</URL>
        <Description>SUSE Bug 1054653</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1058214</URL>
        <Description>SUSE Bug 1058214</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1066430</URL>
        <Description>SUSE Bug 1066430</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1071709</URL>
        <Description>SUSE Bug 1071709</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.</Note>
    </Notes>
    <CVE>CVE-2017-14867</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>9</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-14867.html</URL>
        <Description>CVE-2017-14867</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1060377</URL>
        <Description>SUSE Bug 1060377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1060378</URL>
        <Description>SUSE Bug 1060378</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1061041</URL>
        <Description>SUSE Bug 1061041</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.</Note>
    </Notes>
    <CVE>CVE-2017-15298</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.6</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-15298.html</URL>
        <Description>CVE-2017-15298</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1063412</URL>
        <Description>SUSE Bug 1063412</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.</Note>
    </Notes>
    <CVE>CVE-2017-8386</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-8386.html</URL>
        <Description>CVE-2017-8386</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1038395</URL>
        <Description>SUSE Bug 1038395</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.</Note>
    </Notes>
    <CVE>CVE-2018-11233</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-11233.html</URL>
        <Description>CVE-2018-11233</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1095218</URL>
        <Description>SUSE Bug 1095218</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.</Note>
    </Notes>
    <CVE>CVE-2018-11235</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-11235.html</URL>
        <Description>CVE-2018-11235</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1095219</URL>
        <Description>SUSE Bug 1095219</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.</Note>
    </Notes>
    <CVE>CVE-2018-17456</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-17456.html</URL>
        <Description>CVE-2018-17456</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1110949</URL>
        <Description>SUSE Bug 1110949</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.</Note>
    </Notes>
    <CVE>CVE-2018-19486</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-19486.html</URL>
        <Description>CVE-2018-19486</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1117257</URL>
        <Description>SUSE Bug 1117257</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.</Note>
    </Notes>
    <CVE>CVE-2019-1348</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1348.html</URL>
        <Description>CVE-2019-1348</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.</Note>
    </Notes>
    <CVE>CVE-2019-1349</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1349.html</URL>
        <Description>CVE-2019-1349</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158787</URL>
        <Description>SUSE Bug 1158787</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.</Note>
    </Notes>
    <CVE>CVE-2019-1350</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1350.html</URL>
        <Description>CVE-2019-1350</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158788</URL>
        <Description>SUSE Bug 1158788</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.</Note>
    </Notes>
    <CVE>CVE-2019-1351</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1351.html</URL>
        <Description>CVE-2019-1351</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158789</URL>
        <Description>SUSE Bug 1158789</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.</Note>
    </Notes>
    <CVE>CVE-2019-1352</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1352.html</URL>
        <Description>CVE-2019-1352</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158787</URL>
        <Description>SUSE Bug 1158787</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158790</URL>
        <Description>SUSE Bug 1158790</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.</Note>
    </Notes>
    <CVE>CVE-2019-1353</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1353.html</URL>
        <Description>CVE-2019-1353</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158791</URL>
        <Description>SUSE Bug 1158791</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1352, CVE-2019-1387.</Note>
    </Notes>
    <CVE>CVE-2019-1354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1354.html</URL>
        <Description>CVE-2019-1354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158792</URL>
        <Description>SUSE Bug 1158792</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.</Note>
    </Notes>
    <CVE>CVE-2019-1387</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-1387.html</URL>
        <Description>CVE-2019-1387</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158793</URL>
        <Description>SUSE Bug 1158793</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.</Note>
    </Notes>
    <CVE>CVE-2019-19604</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-19604.html</URL>
        <Description>CVE-2019-19604</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158785</URL>
        <Description>SUSE Bug 1158785</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1158795</URL>
        <Description>SUSE Bug 1158795</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git's "store" helper - Git's "cache" helper - the "osxkeychain" helper that ships in Git's "contrib" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.</Note>
    </Notes>
    <CVE>CVE-2020-11008</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-11008.html</URL>
        <Description>CVE-2020-11008</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1169936</URL>
        <Description>SUSE Bug 1169936</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1170741</URL>
        <Description>SUSE Bug 1170741</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can inject unintended values into the credential helper protocol stream, causing the credential helper to retrieve the password for one server (e.g., good.example.com) for an HTTP request being made to another server (e.g., evil.example.com), resulting in credentials for the former being sent to the latter. There are no restrictions on the relationship between the two, meaning that an attacker can craft a URL that will present stored credentials for any host to a host of their choosing. The vulnerability can be triggered by feeding a malicious URL to git clone. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The problem has been patched in the versions published on April 14th, 2020, going back to v2.17.x. Anyone wishing to backport the change further can do so by applying commit 9a6bbee (the full release includes extra checks for git fsck, but that commit is sufficient to protect clients against the vulnerability). The patched versions are: 2.17.4, 2.18.3, 2.19.4, 2.20.3, 2.21.2, 2.22.3, 2.23.2, 2.24.2, 2.25.3, 2.26.1.</Note>
    </Notes>
    <CVE>CVE-2020-5260</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-5260.html</URL>
        <Description>CVE-2020-5260</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1168930</URL>
        <Description>SUSE Bug 1168930</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1169936</URL>
        <Description>SUSE Bug 1169936</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1170741</URL>
        <Description>SUSE Bug 1170741</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March 9th, 2021. As a workaound, if symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. Likewise, if no clean/smudge filters such as Git LFS are configured globally (i.e. _before_ cloning), the attack is foiled. As always, it is best to avoid cloning repositories from untrusted sources. The earliest impacted version is 2.14.2. The fix versions are: 2.30.1, 2.29.3, 2.28.1, 2.27.1, 2.26.3, 2.25.5, 2.24.4, 2.23.4, 2.22.5, 2.21.4, 2.20.5, 2.19.6, 2.18.5, 2.17.62.17.6.</Note>
    </Notes>
    <CVE>CVE-2021-21300</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:git-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-arch-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-core-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-gnome-keyring-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-credential-libsecret-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-cvs-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-daemon-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-doc-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-email-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-gui-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-p4-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-svn-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:git-web-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:gitk-2.33.0-1.3</ProductID>
        <ProductID>openSUSE Tumbleweed:perl-Git-2.33.0-1.3</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-21300.html</URL>
        <Description>CVE-2021-21300</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1183026</URL>
        <Description>SUSE Bug 1183026</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
