CVE-2017-8386
Summary
| CVE | CVE-2017-8386 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-01 16:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.04 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 24 | All | All | All |
| Operating System | Fedoraproject | Fedora | 25 | All | All | All |
| Operating System | Fedoraproject | Fedora | 26 | All | All | All |
| Operating System | Fedoraproject | Fedora | 24 | All | All | All |
| Operating System | Fedoraproject | Fedora | 25 | All | All | All |
| Operating System | Fedoraproject | Fedora | 26 | All | All | All |
| Application | Git | Git-shell | - | All | All | All |
| Application | Git | Git-shell | - | All | All | All |
| Operating System | Opensuse | Leap | 42.1 | All | All | All |
| Operating System | Opensuse | Leap | 42.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3848-1 git | DEBIAN | www.debian.org | Third Party Advisory, VDB Entry |
| USN-3287-1: Git vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | Exploit, Third Party Advisory |
| [SECURITY] Fedora 26 Update: git-2.13.0-1.fc26 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Git Lets Remote Authenticated Users Escape the 'git-shell' and Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory |
| 3ec804490a265f4c418a321428c12f3f18b7eff5 - pub/scm/git/git - Git at Google | CONFIRM | kernel.googlesource.com | Third Party Advisory |
| openSUSE-SU-2017:1422-1: moderate: Security update for git | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 25 Update: git-2.9.4-1.fc25 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 26 Update: git-2.13.0-1.fc26 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Git: Security bypass (GLSA 201706-04) — Gentoo security | GENTOO | security.gentoo.org | |
| Git CVE-2017-8386 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 24 Update: git-2.7.5-1.fc24 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [ANNOUNCE] Git v2.12.3 and others - Junio C Hamano | MLIST | public-inbox.org | Mailing List, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 25 Update: git-2.9.4-1.fc25 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 24 Update: git-2.7.5-1.fc24 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Git Shell Bypass By Abusing Less (CVE-2017-8386) – Insinuator.net | MISC | insinuator.net | Mitigation, Third Party Advisory |
| [ANNOUNCE] Git v2.12.3 and others - Junio C Hamano | public-inbox.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710369 Gentoo Linux Git Security bypass Vulnerability (GLSA 201706-04)