Git LFS 2.12.0 allows Remote Code Execution.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://legalhackers.com | third party advisory |
https://exploitbox.io | third party advisory exploit |
https://github.com/git-lfs/git-lfs/releases | third party advisory release notes |
https://legalhackers.com/advisories/Git-LFS-RCE-Exploit-CVE-2020-27955.html | third party advisory exploit |
http://seclists.org/fulldisclosure/2020/Nov/1 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/159923/git-lfs-Remote-Code-Execution.html | exploit vdb entry third party advisory |
http://packetstormsecurity.com/files/164180/Git-git-lfs-Remote-Code-Execution.html | exploit vdb entry third party advisory |