CVE-2021-21300 describes a critical remote code execution (RCE) vulnerability in Git, affecting versions 2.14.2 and later, including Git for Windows, macOS, and various Linux distributions. This flaw allows an attacker to execute arbitrary code on a victim's machine by crafting a malicious Git repository that leverages symbolic links and clean/smudge filters (like Git LFS) on case-insensitive file systems. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a high potential for impact, including complete compromise of confidentiality, integrity, and availability. Exploitation requires user interaction (cloning a malicious repository) but has low attack complexity once the repository is crafted. While not listed on CISA's KEV catalog, exploit intelligence confirms the existence of a Metasploit module for this vulnerability, and it has garnered significant community attention with multiple discussions and media coverage. This suggests a high likelihood of exploitation in the wild, emphasizing the urgency of applying available patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.14.2CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.17.0, < 2.17.6CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.18.0, < 2.18.5CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.19.0, < 2.19.6CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.20.0, < 2.20.5CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.