CVE-2020-27955
CRITICALGit Remote Code Execution via git-lfs (CVE-2020-27955)
Title source: metasploitExploitation Summary
EIP tracks 19 public exploits for CVE-2020-27955.
PoCs published by ExploitBox, r00t4dm, DeeLMind, including Metasploit module exploits/windows/http/git_lfs_rce.
AI-analyzed exploit summary This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, targeting Git LFS on Windows. The exploit leverages a vulnerability in Git LFS to achieve remote code execution (RCE) via a malicious payload.
Description
Git LFS 2.12.0 allows Remote Code Execution.
Exploits (19)
This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, targeting Git LFS on Windows. The exploit leverages a vulnerability in Git LFS to achieve remote code execution (RCE) via a malicious payload.
This repository contains only a README.md referencing a Medium article about CVE-2020-27955, a Git LFS vulnerability leading to remote code execution. No actual exploit code or PoC is present.
This Go-based PoC exploits CVE-2020-27955, a Git-LFS RCE vulnerability affecting multiple Git clients on Windows. It spawns a reverse shell to localhost:1337 or launches calc.exe if no listener is available.
This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting multiple Git clients on Windows. The exploit leverages a malicious Git-LFS configuration to execute arbitrary commands via PowerShell.
This PoC demonstrates a Git LFS command injection vulnerability (CVE-2020-27955) by exploiting improper handling of Git LFS track patterns to execute arbitrary commands (e.g., `calc.exe`) during repository operations.
The repository contains only a README.md with a placeholder description for CVE-2020-27955, lacking any functional exploit code or technical details.
This repository contains a proof-of-concept exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability. The exploit leverages a PowerShell reverse shell script to achieve RCE on vulnerable Git clients.
This repository contains a working proof-of-concept exploit for CVE-2020-27955, which leverages a vulnerability in Git-LFS to achieve remote code execution via a malicious repository. The exploit uses a PowerShell reverse shell script to establish a connection back to an attacker-controlled host.
The repository contains only a README.md with the CVE ID and no functional exploit code or technical details. It appears to be a placeholder or incomplete submission.
This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, targeting Git LFS on Windows. The vulnerability allows remote code execution via malicious Git LFS configurations in affected Git clients.
This repository contains a writeup and references for CVE-2020-27955, a Git-LFS Remote Code Execution (RCE) vulnerability affecting various Git clients on Windows. It includes links to advisories, a video PoC, and mentions a Go-based exploit version.
The provided script is a trivial shell command that removes a directory, lacking any exploit logic or vulnerability demonstration for CVE-2020-27955. It does not interact with the target software or demonstrate the vulnerability.
This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting multiple Git clients on Windows. The exploit leverages a malicious Git repository to execute arbitrary commands via a crafted PowerShell script.
This repository contains a PowerShell-based reverse shell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability. The exploit leverages a malicious Git repository to execute arbitrary commands on Windows systems.
This Metasploit module exploits CVE-2020-27955, a vulnerability in Git LFS that allows remote code execution on Windows systems when a victim clones a malicious repository. The exploit sets up a malicious Git repository with a crafted .gitattributes file and a payload disguised as a Git LFS object.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H