ZeroHour

CVE-2017-17831

PoC
CVSS 3.0
8.8 high
EPSS
4%p89
Published
()
Modified
Description

GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.

Vendors
git large file storage project
Products
git large file storage
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.