Lucene search

K
hackeroneJoernchenH1:260005
HistoryAug 14, 2017 - 8:53 p.m.

Internet Bug Bounty: RCE via ssh:// URIs in multiple VCS

2017-08-1420:53:18
joernchen
hackerone.com
51

0.552 Medium

EPSS

Percentile

97.7%

I’d like to submit an RCE issue within Git SVN and Mercurial, the CVEs are:

  • CVE-2017-9800 (Subversion)
  • CVE-2017-1000116 (Mercurial (hg))
  • CVE-2017-1000117 (Git)

Further Info can be found at:

http://blog.recurity-labs.com/2017-08-10/scm-vulns

And product specific:

I think these issues which all are based on the same flaw could be worth
an IBB Bounty. However I’d like to point out that we at Recurity Labs
would like the bounty being donated to a charity. The to be determined
charity will be something in the field of brain aneurysm, this is due to
the fact that Felix, the founder of Recurity Labs, currently is
recovering from a brain aneurysm.

So, just let us know what you think about this.

Cheers,

joern

P.S. I took the CVSS Score from the Subversion Advisory
the Redhat advisory states a score of 6.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L) I guess the truth is somewhere in between.