{"id":"CVE-2017-17831","details":"GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a \"url =\" line in a .lfsconfig file within a repository.","aliases":["GHSA-w4xh-w33p-4v29","GO-2021-0073"],"modified":"2026-07-08T11:35:58.983395Z","published":"2017-12-21T06:29:00.243Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102926"},{"type":"ADVISORY","url":"https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2018-01-24-942834324.html"},{"type":"ADVISORY","url":"https://github.com/git-lfs/git-lfs/releases/tag/v2.1.1"},{"type":"FIX","url":"https://github.com/git-lfs/git-lfs/pull/2242"},{"type":"EVIDENCE","url":"http://blog.recurity-labs.com/2017-08-10/scm-vulns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/git-lfs/git-lfs","events":[{"introduced":"0"},{"fixed":"3314e2878fcc3224774a96b78183e111fbd8ac5b"}],"database_specific":{"cpe":"cpe:2.3:a:git_large_file_storage_project:git_large_file_storage:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.1.0","v2.0.2-rc1","v2.0.0","v1.5.0","v1.4.3","v1.4.4","v1.4.2","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.0","v1.1.1-pre-push-tracing","v1.1.1","v1.1.0","v1.0.2","v1.0.1","v1.0.0","v0.6.0","v0.5.3","v0.5.2","v0.5.1","v0.5.1-tracing","v0.5.0","v0.5.0.pre1","v0.4.1","v0.4.0","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.3","v0.2.2","v0.2.1","v0.2.1-p1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-17831.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}