← All CVEs

CVE-2017-14867

high · 8.8

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

8.8
CVSS
36.0%
EPSS (exploit prob.)
98th
EPSS percentile
2017-09-29
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
git-scmgit<= 2.10.4
git-scmgit2.11.0
git-scmgit2.11.1
git-scmgit2.11.2
git-scmgit2.11.3
git-scmgit2.12.0
git-scmgit2.12.1
git-scmgit2.12.2
git-scmgit2.12.3
git-scmgit2.12.4
git-scmgit2.13.0
git-scmgit2.13.1
git-scmgit2.13.2
git-scmgit2.13.3
git-scmgit2.13.4
git-scmgit2.13.5
git-scmgit2.14.0
git-scmgit2.14.1
debiandebian_linux8.0
debiandebian_linux9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-14867