GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HGit Large File Storage Project Git Large File Storage
APPGit Large File Storage Project< 2.1.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References
Related vulnerabilities
CVE-2022-24826CRITICAL9.8PL ✓same product
RCE w Git LFS na Windows via podatność CWE-426 (untrusted search path)
CVE-2020-27955CRITICAL9.8PL ✓same product
RCE w Git Large File Storage (Git LFS) 2.12.0
CVE-2021-21237HIGH7.2same product
Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a ma...