Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4xh-w33p-4v29

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

GitHub Git LFS Arbitrary command execution vulnerability

GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a url = line in a .lfsconfig file within a repository.

Specific Go Packages Affected

github.com/git-lfs/git-lfs/lfsapi

Пакеты

Наименование

github.com/git-lfs/git-lfs

go
Затронутые версииВерсия исправления

< 2.1.1-0.20170519163204-f913f5f9c7c6

2.1.1-0.20170519163204-f913f5f9c7c6

EPSS

Процентиль: 72%
0.00729
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.

CVSS3: 8.8
nvd
около 8 лет назад

GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.

CVSS3: 8.8
debian
около 8 лет назад

GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitra ...

EPSS

Процентиль: 72%
0.00729
Низкий

8.8 High

CVSS3

Дефекты

CWE-20