Vulnerabilities > Dulwich Project

DATE CVE VULNERABILITY TITLE RISK
2017-10-29 CVE-2017-16228 Unspecified vulnerability in Dulwich Project Dulwich
Dulwich before 0.18.5, when an SSH subprocess is used, allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.
network
low complexity
dulwich-project
critical
9.8