CVE-2020-27955
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
05/11/2020
Last modified:
16/12/2021
Description
Git LFS 2.12.0 allows Remote Code Execution.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:git_large_file_storage_project:git_large_file_storage:2.12.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/159923/git-lfs-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/164180/Git-git-lfs-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2020/Nov/1
- https://exploitbox.io
- https://github.com/git-lfs/git-lfs/releases
- https://legalhackers.com
- https://legalhackers.com/advisories/Git-LFS-RCE-Exploit-CVE-2020-27955.html