CVE-2018-17456 is a critical remote code execution vulnerability affecting Git versions before 2.14.5, 2.15.3, 2.16.5, 2.17.2, 2.18.1, and 2.19.1, impacting products from Canonical, Debian, Git-SCM, and Red Hat. This flaw allows an attacker to execute arbitrary code when a user performs a recursive "git clone" of a superproject containing a malicious .gitmodules file with a URL field starting with a hyphen. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit modules are available in Metasploit and ExploitDB, indicating a high potential for exploitation, further supported by significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.14.0, < 2.14.5CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.15.0, < 2.15.3CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.16.0, < 2.16.5CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.17.0, < 2.17.2CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.18.0, < 2.18.1CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.