Vulnerabilities
Vulnerable Software
Git-Scm:  >> Git  >> 2.18.2  Security Vulnerabilities
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVSS Score
7.8
EPSS Score
0.013
Published
2019-12-11
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.
CVSS Score
9.8
EPSS Score
0.007
Published
2018-11-23


Contact Us

Shodan ® - All rights reserved