GHSA-jjxg-hpm7-g95f

Suggest an improvement
Source
https://github.com/advisories/GHSA-jjxg-hpm7-g95f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jjxg-hpm7-g95f/GHSA-jjxg-hpm7-g95f.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jjxg-hpm7-g95f
Aliases
Published
2022-05-13T01:43:20Z
Modified
2026-05-29T22:41:17Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bazaar allows remote attackers to execute arbitrary commands via a bzr+ssh URL with initial dash character in hostname
Details

Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-29T22:19:41Z",
    "nvd_published_at": "2017-11-27T10:29:00Z",
    "severity": "HIGH"
}
References

Affected packages

PyPI / bzr

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.7.0

Affected versions

2.*
2.6.0
2.7.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jjxg-hpm7-g95f/GHSA-jjxg-hpm7-g95f.json"