CVE Vulnerabilities

CVE-2017-8386

Published: Jun 01, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Affected Software

NameVendorStart VersionEnd Version
Git-shellGit- (including)- (including)
Red Hat Enterprise Linux 7RedHatgit-0:1.8.3.1-11.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-git29-git-0:2.9.3-3.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-git29-git-0:2.9.3-3.el7*
GitUbuntuesm-infra/xenial*
GitUbuntutrusty*
GitUbuntuupstream*
GitUbuntuxenial*
GitUbuntuyakkety*
GitUbuntuzesty*

References