vulnerability

Amazon Linux AMI: ALAS-2017-910: Security patch for git

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
10/12/2017
Added
10/13/2017
Modified
02/19/2025

Description

The git subcommand cvsserver is a Perl script which makes excessive use of the backtick operator to invoke git. Unfortunately user input is used within some of those invocations. It should be noted, that git-cvsserver will be invoked by git-shell by default without further configuration.


http://seclists.org/oss-sec/2017/q3/534

Solution

amazon-linux-upgrade-git
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.