← All CVEs

CVE-2014-9390

critical · 9.8

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

9.8
CVSS
75.6%
EPSS (exploit prob.)
99th
EPSS percentile
2020-02-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
git-scmgit< 1.8.5.6
git-scmgit>= 1.9.0, < 1.9.5
git-scmgit>= 2.0.0, < 2.0.5
git-scmgit>= 2.1.0, < 2.1.4
git-scmgit>= 2.2.0, < 2.2.1
applemac_os_xall versions
microsoftwindowsall versions
mercurialmercurial< 3.2.3
applemac_os_xall versions
microsoftwindowsall versions
applexcode<= 6.1.1
applexcode6.2
applexcode6.2
eclipseegit< 08-12-2014
eclipsejgit< 3.4.2
eclipsejgit>= 3.5.0, < 3.5.3
libgit2libgit2< 0.21.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-9390