← All CVEs

CVE-2018-17456

critical · 9.8

Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.

9.8
CVSS
97.4%
EPSS (exploit prob.)
100th
EPSS percentile
2018-10-06
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-88

Affected products

VendorProductAffected versions
git-scmgit>= 2.14.0, < 2.14.5
git-scmgit>= 2.15.0, < 2.15.3
git-scmgit>= 2.16.0, < 2.16.5
git-scmgit>= 2.17.0, < 2.17.2
git-scmgit>= 2.18.0, < 2.18.1
git-scmgit>= 2.19.0, < 2.19.1
redhatansible_tower3.3
redhatenterprise_linux6.0
redhatenterprise_linux6.7
redhatenterprise_linux7.0
redhatenterprise_linux7.3
redhatenterprise_linux7.4
redhatenterprise_linux7.5
redhatenterprise_linux7.6
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_eus7.6
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_workstation7.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
debiandebian_linux9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-17456