Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34211
HistoryFeb 14, 2022 - 9:57 a.m.

Remote Code Execution (RCE)

2022-02-1409:57:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
remote code execution
github
git-lfs
execcommand
subprocess_windows.go
inject code
malicious repository
software

EPSS

0.954

Percentile

99.4%

github.com/git-lfs/git-lfs is vulnerable to remote code execution. The vulnerability exists in ‘ExecCommand’ function of subprocess_windows.go which allows an attacker to inject and execute codes in the root directory of a malicious repository by simply adding an executable files.