Description
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-938-1 | git security update |
Debian DSA |
DSA-3848-1 | git security update |
Ubuntu USN |
USN-3287-1 | Git vulnerability |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:34:22.740Z
Reserved: 2017-05-01T00:00:00.000Z
Link: CVE-2017-8386
No data.
Status : Deferred
Published: 2017-06-01T16:29:00.450
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8386
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN