Loading
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.
Use CWE-78, Git-Scm vendor hub and Git product page to widen CVE-2017-14867 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48384, CVE-2022-41903 and CVE-2022-23521 for nearby disclosures in the same product family.