CVE-2017-8386
HIGH 8.8EPSS 12.4%
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 12.39% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2017-06-01
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- cyberharsh/Gitcve-2017-83860★ · 2020-06-20
- suz1n/WHS3_vulhub0★ · 2025-04-27