← All CVEs

CVE-2015-7545

critical · 9.8

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

9.8
CVSS
18.7%
EPSS (exploit prob.)
97th
EPSS percentile
2016-04-13
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20CWE-284

Affected products

VendorProductAffected versions
git_projectgit<= 2.3.9
git_projectgit2.4.0
git_projectgit2.4.1
git_projectgit2.4.2
git_projectgit2.4.3
git_projectgit2.4.4
git_projectgit2.4.5
git_projectgit2.4.6
git_projectgit2.4.7
git_projectgit2.4.8
git_projectgit2.4.9
git_projectgit2.5.0
git_projectgit2.5.1
git_projectgit2.5.2
git_projectgit2.5.3
git_projectgit2.6.0
redhatsoftware_collections1.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.04
canonicalubuntu_linux15.10
opensuseopensuse13.1
opensuseopensuse13.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-7545