CVE-2017-8386

HIGH

git <2.4.12-2.12.3 - Privilege Escalation

Title source: llm

Description

git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.

Exploits (1)

nomisec WRITEUP
by suz1n · poc
https://github.com/suz1n/WHS3_vulhub

Scores

CVSS v3 8.8
EPSS 0.7273
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (10)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 16.10
canonical/ubuntu_linux 17.04
debian/debian_linux 8.0
fedoraproject/fedora 24
fedoraproject/fedora 25
fedoraproject/fedora 26
git/git-shell
opensuse/leap 42.1
Published Jun 01, 2017
Tracked Since Feb 18, 2026