Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5598
HistoryDec 22, 2017 - 2:56 a.m.

Remote Command Execution (RCE)

2017-12-2202:56:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.005

Percentile

76.3%

github.com/git-lfs/git-lfs is vulnerable to remote code execution (RCE) attacks. The application does not sanitize ssh:// URLs passed to it, allowing a malicious user to execute arbitrary commands.