← Vulnerability feed

Vulnerability record · CVE-2008-5517 · published 13 January 2009

CVE-2008-5517: Git code injection vulnerability

Git · Git

The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.

7.5 CVSS 2.0 High EPSS 12% · top 4.0% CWE-94 · Code injection
7.5CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512330
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00002.html
http://repo.or.cz/w/git.git?a=commitdiff%3Bh=516381d5
http://secunia.com/advisories/33964 Vendor Advisory
http://secunia.com/advisories/34194 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0005
http://www.debian.org/security/2009/dsa-1708
http://www.gentoo.org/security/en/glsa/glsa-200903-15.xml
http://www.openwall.com/lists/oss-security/2009/01/20/1
http://www.openwall.com/lists/oss-security/2009/01/21/7
http://www.openwall.com/lists/oss-security/2009/01/23/2
http://www.securityfocus.com/archive/1/500008/100/0/threaded
http://www.securityfocus.com/bid/33215 Patch
http://www.ubuntu.com/usn/USN-723-1
http://www.vupen.com/english/advisories/2009/0175 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=479715
https://issues.rpath.com/browse/RPL-2936
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512330
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00002.html
http://repo.or.cz/w/git.git?a=commitdiff%3Bh=516381d5
http://secunia.com/advisories/33964 Vendor Advisory
http://secunia.com/advisories/34194 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0005
http://www.debian.org/security/2009/dsa-1708
http://www.gentoo.org/security/en/glsa/glsa-200903-15.xml
http://www.openwall.com/lists/oss-security/2009/01/20/1
http://www.openwall.com/lists/oss-security/2009/01/21/7
http://www.openwall.com/lists/oss-security/2009/01/23/2
http://www.securityfocus.com/archive/1/500008/100/0/threaded
http://www.securityfocus.com/bid/33215 Patch
http://www.ubuntu.com/usn/USN-723-1
http://www.vupen.com/english/advisories/2009/0175 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=479715
https://issues.rpath.com/browse/RPL-2936

Track CVE-2008-5517 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-25648Git argument injection vulnerabilityThe package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) fu…EPSS 4.9%9.0CVE-2024-32002Git path traversal vulnerabilityGit is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be c…EPSS 29%7.5CVE-2024-52005Git vulnerabilityGit is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the …EPSS 0.51%7.5CVE-2020-5260Git improper input validation vulnerabilityAffected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git us…EPSS 10%7.5CVE-2008-5516Git os command injection vulnerabilityThe web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se…EPSS 4.4%7.5CVE-2008-3546Git memory buffer overflow vulnerabilityStack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrar…EPSS 4.3%7.5CVE-2006-0477Git vulnerabilityBuffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic li…EPSS 3.3%5.0CVE-2009-2108Git vulnerabilitygit-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contai…EPSS 5.8%

Source: NIST National Vulnerability Database (record CVE-2008-5517), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.