HIGH🇵🇱 Wersja polska

CVE-2015-8968

CVSS 8.8v3.1pub. 2016-11-03upd. 2026-05-06

git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit this. The ext command will be run if the repository is recursively cloned or if submodules are updated. This attack works when cloning both local and remote repositories.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Squareup Git Fastclone

    APP
    Squareup
    < 1.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2015-8969CRITICAL9.8PL ✓same product

Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń

CVE-2018-1000844CRITICAL9.1PL ✓same vendor

XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF

CVE-2026-45799HIGH7.5PL ✓same vendor

Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi

CVE-2018-1000850HIGH7.5same vendor

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vul...

CVE-2023-0833MEDIUM4.7same vendor

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information d...