8.8
CVE-2017-8386
- EPSS 12.39%
- Veröffentlicht 01.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.10
Canonical ≫ Ubuntu Linux Version 17.04
Fedoraproject ≫ Fedora Version 24
Fedoraproject ≫ Fedora Version 25
Fedoraproject ≫ Fedora Version 26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 12.39% | 0.957 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
https://access.redhat.com/errata/RHSA-2017:2004
http://lists.opensuse.org/opensuse-updates/2017-05/msg00090.html
http://public-inbox.org/git/xmqq8tm5ziat.fsf%40gitster.mtv.corp.google.com/
http://www.debian.org/security/2017/dsa-3848
http://www.securityfocus.com/bid/98409
http://www.securitytracker.com/id/1038479
http://www.ubuntu.com/usn/USN-3287-1
https://access.redhat.com/errata/RHSA-2017:2491
https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/
https://kernel.googlesource.com/pub/scm/git/git/+/3ec804490a265f4c418a321428c12f3f18b7eff5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ISHYFLM2ACYHHY3JHCLF75X7UF4ZMDM/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPYRN7APMHY4ZFDPAKD22J5R4QJFY2JP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FDS3LSJJ3YGGQYIVPKQDVOCXWDSF6JGF/
https://security.gentoo.org/glsa/201706-04