CVE Vulnerabilities

CVE-2017-8386

Published: Jun 01, 2017 | Modified: May 13, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Affected Software

NameVendorStart VersionEnd Version
Git-shellGit- (including)- (including)
Red Hat Enterprise Linux 7RedHatgit-0:1.8.3.1-11.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-git29-git-0:2.9.3-3.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-git29-git-0:2.9.3-3.el7*
GitUbuntuesm-infra-legacy/xenial*
GitUbuntuesm-infra/xenial*
GitUbuntutrusty*
GitUbuntuupstream*
GitUbuntuxenial*
GitUbuntuyakkety*
GitUbuntuzesty*

References