AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-14867

HIGH · CVSS 8.8 EPSS 35.76%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-09-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. Its EPSS score suggests a 35.8% probability of exploitation in the next 30 days.

CVE
CVE-2017-14867
Severity
HIGH
CVSS
8.8
EPSS
35.76%

Original NVD Description

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

Related CVEs

Other vulnerabilities affecting the same vendor(s)