GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a url =
line in a .lfsconfig
file within a repository.
github.com/git-lfs/git-lfs/lfsapi
{ "nvd_published_at": "2017-12-21T06:29:00Z", "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-02-08T00:28:40Z" }