Uncontrolled Search Path Element The advisory has been revoked - it doesn't affect any version of package git-lfs  (opens in a new tab)


Threat Intelligence

EPSS
94.47% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-GITLFS-1037634
  • published6 Nov 2020
  • disclosed5 Nov 2020

Introduced: 5 Nov 2020

CVE-2020-27955  (opens in a new tab)
CWE-427  (opens in a new tab)

Amendment

The Debian security team deemed this advisory irrelevant for Debian:10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream git-lfs package and not the git-lfs package as distributed by Debian.

Git LFS 2.12.0 allows Remote Code Execution.