Security Advisory

CVE-2017-14867

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-28 14:00:00
Last updated 2024-08-05 19:42:21
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.