ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
{
"cpe": "cpe:2.3:a:xrootd:xrootd:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "4.6.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000215.json"
"2026-07-08T15:10:13Z"
[
{
"signature_version": "v1",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"id": "CVE-2017-1000215-2fcbb095",
"digest": {
"length": 853.0,
"function_hash": "112229951031899810966736752844636854031"
},
"target": {
"function": "DefaultEnv::Initialize",
"file": "src/XrdCl/XrdClDefaultEnv.cc"
},
"deprecated": false,
"signature_type": "Function"
},
{
"signature_version": "v1",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"id": "CVE-2017-1000215-3b1688e8",
"digest": {
"threshold": 0.9,
"line_hashes": [
"260447500710362873653222888231281706120",
"168260783410019927119455854970863716722",
"247493570141953087084775661652092473438",
"135900543264337591286564561712387614237"
]
},
"target": {
"file": "src/XrdCl/XrdClDefaultEnv.cc"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
"id": "CVE-2017-1000215-ca0285d5",
"digest": {
"threshold": 0.9,
"line_hashes": [
"181478029663018906132982824937374166085",
"101470276272918895569508917481344862435",
"245241373668172469645022560991818677098",
"234654514818673332220354279859210750508"
]
},
"target": {
"file": "src/XrdVersionPlugin.hh"
},
"deprecated": false,
"signature_type": "Line"
}
]