Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-8386

Опубликовано: 05 мая 2017
Источник: redhat
CVSS3: 5
EPSS Высокий

Описание

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

A flaw was found in the way git-shell handled command-line options for the restricted set of git-shell commands. A remote, authenticated attacker could use this flaw to bypass git-shell restrictions, to view and manipulate files, by abusing the instance of the less command launched using crafted command-line options.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitWill not fix
Red Hat Enterprise Linux 7gitFixedRHSA-2017:200401.08.2017
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-git29-gitFixedRHSA-2017:249117.08.2017
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git29-gitFixedRHSA-2017:249117.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 99%
0.75646
Высокий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 8.8
nvd
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 8.8
debian
больше 8 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7 ...

suse-cvrf
больше 8 лет назад

Security update for git

suse-cvrf
больше 8 лет назад

Security update for git

EPSS

Процентиль: 99%
0.75646
Высокий

5 Medium

CVSS3