Lack of data validation In github.com/git-lfs/git-lfs/lfsapi
Description
GitHub Git LFS Arbitrary command execution vulnerability
GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a url = line in a .lfsconfig file within a repository.
Specific Go Packages Affected
github.com/git-lfs/git-lfs/lfsapi
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v2.1.1-0.20170519163204-f913f5f9c7c6 | ||
go | 2.1.1-0.20170519163204-f913f5f9c7c6 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.