CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 97.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 97.36% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- git-scm/git · redhat/ansible tower · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html
- http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105523Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107511Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041811Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3408Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3541Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0316
- https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404Patch, Third Party Advisory
- https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46Patch, Third Party Advisory
- https://marc.info/?l=git&m=153875888916397&w=2Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/30Mailing List, Third Party Advisory
- https://usn.ubuntu.com/3791-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4311Third Party Advisory
- https://www.exploit-db.com/exploits/45548/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/45631/Exploit, Third Party Advisory, VDB Entry
- https://www.openwall.com/lists/oss-security/2018/10/06/3Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html
- http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105523Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107511Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041811Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3408Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3541Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0316
- https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404Patch, Third Party Advisory
- https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46Patch, Third Party Advisory
- https://marc.info/?l=git&m=153875888916397&w=2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.