Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2014-9390

CRITICAL 9.8

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 75.04% exploit likely percentile 99.5%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Git Windows winget:Git.Git
    Affected ≥2.2.0 <2.2.1 Fixed in 2.2.1 Latest tracked 2.55.0.3 patched
  • Xcode macOS com.apple.dt.Xcode
    Affected Fixed in Latest tracked 26.6 undetermined

NVD references 8 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (8)
Vendor Product Versions
git-scm git
All platforms (wildcard)
<1.8.5.6
git-scm git
All platforms (wildcard)
≥1.9.0 <1.9.5
git-scm git
All platforms (wildcard)
≥2.0.0 <2.0.5
git-scm git
All platforms (wildcard)
≥2.1.0 <2.1.4
git-scm git
All platforms (wildcard)
≥2.2.0 <2.2.1
apple xcode
All platforms (wildcard)
≤6.1.1
apple xcode
All platforms (wildcard)
apple xcode
All platforms (wildcard)
View on NVD ↗ Advisory · support.apple.com Advisory · github.com Advisory · news.ycombinator.com