Exploitation Summary
EIP tracks 2 public exploits for CVE-2017-8386. PoCs published by hhhell, suz1n.
AI-analyzed exploit summary This repository provides a detailed technical analysis and reproduction of CVE-2017-8386, a Git-Shell sandbox bypass vulnerability. The flaw allows authenticated attackers to escape the git-shell restricted environment by exploiting the less pager's interactive command execution via `git-upload-archive --help`.
Description
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Exploits (2)
This repository provides a detailed technical analysis and reproduction of CVE-2017-8386, a Git-Shell sandbox bypass vulnerability. The flaw allows authenticated attackers to escape the git-shell restricted environment by exploiting the less pager's interactive command execution via `git-upload-archive --help`.
This repository provides a detailed writeup and proof-of-concept for CVE-2017-8386, a git-shell sandbox bypass vulnerability. It explains how to exploit the 'less' command within git-shell to achieve remote code execution (RCE).
References (14)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H