Git CVE-2017-8386 Security Bypass Vulnerability
by CIRT Team
Description: git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a – (dash) character.
Impact: Remote attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
26 Oct 2023 - Security Advisories & Alerts