Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2017-14867

HIGH 8.8 Vendor bulletin scale — NVD CVSS pending

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

Attack vector : Network No user interaction
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 35.76% moderate exploit risk percentile 98.3%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Git Windows winget:Git.Git
    Affected Fixed in Latest tracked 2.55.0.3 undetermined
Vulnerable CPE configurations (18)
Vendor Product Versions
git-scm git
All platforms (wildcard)
≤2.10.4
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
git-scm git
All platforms (wildcard)
View on NVD ↗