CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. Its EPSS score suggests a 35.8% probability of exploitation in the next 30 days.
CVE
CVE-2017-14867
Severity
HIGH
CVSS
8.8
EPSS
35.76%
Original NVD Description
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
Related CVEs
Other vulnerabilities affecting the same vendor(s)