Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-8386

Опубликовано: 05 мая 2017
Источник: redhat
CVSS3: 5
EPSS Средний

Описание

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

A flaw was found in the way git-shell handled command-line options for the restricted set of git-shell commands. A remote, authenticated attacker could use this flaw to bypass git-shell restrictions, to view and manipulate files, by abusing the instance of the less command launched using crafted command-line options.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gitWill not fix
Red Hat Enterprise Linux 7gitFixedRHSA-2017:200401.08.2017
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-git29-gitFixedRHSA-2017:249117.08.2017
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-git29-gitFixedRHSA-2017:249117.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 96%
0.12387
Средний

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 9 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 8.8
nvd
около 9 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

CVSS3: 8.8
debian
около 9 лет назад

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7 ...

suse-cvrf
около 9 лет назад

Security update for git

suse-cvrf
около 9 лет назад

Security update for git

EPSS

Процентиль: 96%
0.12387
Средний

5 Medium

CVSS3