Known vulnerabilities in Git LFS
Vendor:
Git
Software:
Git LFS
Software CPE:
cpe:2.3:a:git:git_lfs:*:*:*:*:*:*:*:*
Website:
https://git-scm.com/
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
3.7.1
3.7.0
3.6.1
3.6.0
3.5.1
3.5.0
3.4.1
3.4.0
3.3.0
3.2.0
3.1.4
3.1.3
3.1.2
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.13.3
2.13.2
2.13.1
2.13.0
2.12.1
2.12.0
2.11.0
2.10.0
2.9.2
2.9.1
2.9.0
2.8.0
2.7.2
2.7.1
2.7.0
2.6.1
2.6.0
2.5.2
2.5.1
2.5.0
2.4.2
2.4.1
2.4.0
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.1
2.2.0
2.1.1
0.4.2.1
2.15.1
2.15.0
2.14.3
0.1.0
0.2.0
0.2.1 patch 1
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2
0.4.2 hot fix
0.5.0.pre2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.1
2.0.2
2.1.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62504 - Untrusted Search Path CVE-2022-24826 |
CWE-426 | High | 3.1.3 | 22.04.2022 |
SB2022042209 |
||
| #VU48175 - Improper input validation CVE-2020-27955 |
CWE-20 | High | 2.12.1 | 05.11.2020 |
SB2020110606 SB2022042625 |
||
| #VU10850 - Command injection CVE-2017-17831 |
CWE-77 | Low | - | 06.03.2018 |
SB2017051908 |