Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14867

Опубликовано: 29 сент. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
Версия до 2.10.4 (включая)
cpe:2.3:a:git-scm:git:2.11.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.11.1:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.11.2:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.11.3:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.12.1:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.12.2:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.12.3:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.12.4:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.1:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.2:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.3:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.4:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.13.5:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.14.0:*:*:*:*:*:*:*
cpe:2.3:a:git-scm:git:2.14.1:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.36003
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

CVSS3: 7.8
redhat
почти 9 лет назад

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

CVSS3: 8.8
msrc
около 1 года назад

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

CVSS3: 8.8
debian
почти 9 лет назад

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x ...

suse-cvrf
почти 9 лет назад

Security update for git

EPSS

Процентиль: 98%
0.36003
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78