7.5
CVSSv3

CVE-2018-10857

Published: 16/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

git-annex project git-annex -

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #873088 git-annex: remote code execution via crafted SSH URLs (CVE-2017-12976) Package: git-annex; Maintainer for git-annex is Debian Haskell Group <pkg-haskell-maintainers@listsaliothdebianorg>; Source for git-annex is src:git-annex (PTS, buildd, popcon) Reported by: Antoine Beaupre <anarcat@o ...
Some uses of git-annex were vulnerable to a private data exposure and exfiltration attack It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN ...