Git Large File Storage Project
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-27955 | Cri | 0.73 | 9.8 | 0.83 | Nov 5, 2020 | Git LFS 2.12.0 allows Remote Code Execution. | ||
| CVE-2022-24826 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.… | ||
| CVE-2017-17831 | Hig | 0.50 | 8.8 | 0.04 | Dec 21, 2017 | GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository. | ||
| CVE-2021-21237 | Hig | 0.40 | 7.2 | 0.00 | Jan 15, 2021 | Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repository with a git.bat or git.exe file in the current directory, that program would be executed, permitting the attacker to execute arbitrary code. This does… |
- risk 0.73cvss 9.8epss 0.83
Git LFS 2.12.0 allows Remote Code Execution.
- risk 0.64cvss 9.8epss 0.02
On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be executed, permitting the attacker to execute arbitrary code. This does not affect Unix systems.…
- risk 0.50cvss 8.8epss 0.04
GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.
- risk 0.40cvss 7.2epss 0.00
Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repository with a git.bat or git.exe file in the current directory, that program would be executed, permitting the attacker to execute arbitrary code. This does…