CVE-2014-9390: Apple Xcode
Critical severity, CVSS 9.8. EPSS: 75.6% chance of exploitation in the next 30 days.
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
Affected products
- Apple Xcode: up to and including 6.1.1; version 6.2 only
- Eclipse Egit: before 08-12-2014 (fixed in 08-12-2014)
- Eclipse Jgit: before 3.4.2 (fixed in 3.4.2); from 3.5.0, before 3.5.3 (fixed in 3.5.3)
- Git-Scm Git: before 1.8.5.6 (fixed in 1.8.5.6); from 1.9.0, before 1.9.5 (fixed in 1.9.5); from 2.0.0, before 2.0.5 (fixed in 2.0.5); from 2.1.0, before 2.1.4 (fixed in 2.1.4); from 2.2.0, before 2.2.1 (fixed in 2.2.1)
- LIBGIT2 LIBGIT2: before 0.21.3 (fixed in 0.21.3)
- Mercurial Mercurial: before 3.2.3 (fixed in 3.2.3)
Published 2020-02-12. Last modified 2026-06-17.