Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Git 操作系统命令注入漏洞
Vulnerability Description
Git是美国软件开发者林纳斯-托瓦兹(Linus Torvalds)所研发的一套免费、开源的分布式版本控制系统。 Git中存在安全漏洞。攻击者可借助模块名中的shell元字符利用该漏洞执行任意的操作系统命令。以下版本受到影响:Git 2.10.5之前的版本,2.11.4之前的2.11.x版本,2.12.5之前的2.12.x版本,2.13.6之前的2.13.x版本,2.14.2之前的2.14.x版本。
CVSS Information
N/A
Vulnerability Type
N/A