Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-1000117Open Redirect in GIT

Severity
8.8HIGHNVD
GHSA9.8
EPSS
76.4%
top 1.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 5
Latest updateMay 13

Description

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Debiangit/git< 1:2.14.1-1+3
NVDgit-scm/git2.7.5+28
CVEListV5atlassian/bitbucket_server4 versions+3

🔴Vulnerability Details

4
GHSA
GHSA-q5x8-47cx-6m4p: A malicious third-party can give a crafted "ssh://2022-05-13
GHSA
Dulwich RCE Vulnerability2022-05-13
OSV
CVE-2017-1000117: A malicious third-party can give a crafted "ssh://2017-10-05
CVEList
CVE-2017-1000117: A malicious third-party can give a crafted "ssh://2017-10-04

💥Exploits & PoCs

2
Exploit-DB
Git < 2.7.5 - Command Injection (Metasploit)2017-08-31
Metasploit
Malicious Git HTTP Server For CVE-2017-1000117

📋Vendor Advisories

11
Red Hat
python-dulwich: Setting SSH arguments from untrusted URLs allows code execution2017-10-29
Apple
CVE-2017-7136: Xcode 92017-09-19
Apple
CVE-2017-1000117: Xcode 92017-09-19
Apple
CVE-2017-7076: Xcode 92017-09-19
Apple
CVE-2017-7135: Xcode 92017-09-19

💬Community

4
Bugzilla
CVE-2017-16228 python-dulwich: Setting SSH arguments from untrusted URLs allows code execution2017-11-03
HackerOne
RCE via ssh:// URIs in multiple VCS2017-09-21
Bugzilla
CVE-2017-12976 git-annex: RCE via ssh URL with an initial dash character in the hostname2017-08-24
Bugzilla
CVE-2017-1000117 git: Command injection via malicious ssh URLs2017-08-10
CVE-2017-1000117 — Open Redirect in Git-scm GIT | cvebase