CVE-2017-8386: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 12.4% chance of exploitation in the next 30 days.
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 16.10 only; version 17.04 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 24 only; version 25 only; version 26 only
- Git Git-Shell: affected versions not specified
- Opensuse Leap: version 42.1 only
Published 2017-06-01. Last modified 2026-06-17.