← All CVEs

CVE-2017-8386

high · 8.8

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

8.8
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2017-06-01
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
gitgit-shellall versions
opensuseleap42.1
debiandebian_linux8.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux16.10
canonicalubuntu_linux17.04
fedoraprojectfedora24
fedoraprojectfedora25
fedoraprojectfedora26

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-8386