ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000215.json"
"2026-04-11T04:47:17Z"
[
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"digest": {
"function_hash": "112229951031899810966736752844636854031",
"length": 853.0
},
"id": "CVE-2017-1000215-2fcbb095",
"deprecated": false,
"target": {
"file": "src/XrdCl/XrdClDefaultEnv.cc",
"function": "DefaultEnv::Initialize"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"260447500710362873653222888231281706120",
"168260783410019927119455854970863716722",
"247493570141953087084775661652092473438",
"135900543264337591286564561712387614237"
]
},
"id": "CVE-2017-1000215-3b1688e8",
"deprecated": false,
"target": {
"file": "src/XrdCl/XrdClDefaultEnv.cc"
}
},
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"181478029663018906132982824937374166085",
"101470276272918895569508917481344862435",
"245241373668172469645022560991818677098",
"234654514818673332220354279859210750508"
]
},
"id": "CVE-2017-1000215-ca0285d5",
"deprecated": false,
"target": {
"file": "src/XrdVersionPlugin.hh"
}
}
]