Arbitrary Command Execution Vulnerability in git-annex by git
CVE-2017-12976
8.8HIGH
What is CVE-2017-12976?
git-annex versions prior to 6.20170818 contain a vulnerability that allows remote attackers to execute arbitrary commands. This occurs through the exploitation of an ssh URL with an initial dash character in the hostname. Such configurations exemplify a significant security flaw, enabling attackers to potentially gain unauthorized access and control over the affected systems, drawing parallels with other known vulnerabilities.