GitHub Git LFS Arbitrary command execution vulnerability
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
< 2.1.1-0.20170519163204-f913f5f9c7c6
Patched versions
2.1.1-0.20170519163204-f913f5f9c7c6
Description
Published by the National Vulnerability Database
Dec 21, 2017
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 8, 2023
Last updated
Oct 2, 2023
GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a
url =
line in a.lfsconfig
file within a repository.Specific Go Packages Affected
github.com/git-lfs/git-lfs/lfsapi
References