CVE Vulnerabilities

CVE-2017-8386

Published: Jun 01, 2017 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Affected Software

Name Vendor Start Version End Version
Git-shell Git - (including) - (including)
Red Hat Enterprise Linux 7 RedHat git-0:1.8.3.1-11.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-git29-git-0:2.9.3-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-git29-git-0:2.9.3-3.el7 *
Git Ubuntu trusty *
Git Ubuntu upstream *
Git Ubuntu xenial *
Git Ubuntu yakkety *
Git Ubuntu zesty *

References