git-annex_project CVE Vulnerabilities & Metrics

Focus on git-annex_project vulnerabilities and metrics.

Last updated: 21 Aug 2025, 22:25 UTC

About git-annex_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with git-annex_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total git-annex_project CVEs: 4
Earliest CVE date: 20 Aug 2017, 20:29 UTC
Latest CVE date: 26 Jun 2025, 21:15 UTC

Latest CVE reference: CVE-2014-6274

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical git-annex_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.2

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 3
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS git-annex_project CVEs

These are the five CVEs with the highest CVSS scores for git-annex_project, sorted by severity first and recency.

All CVEs for git-annex_project

git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from 3.20121126 before 5.20140919.

CVE-2018-10857 git-annex_project vulnerability CVSS: 5.0 16 Jul 2018, 20:29 UTC

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

CVE-2018-10859 git-annex_project vulnerability CVSS: 5.0 16 Jul 2018, 18:29 UTC

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex

CVE-2017-12976 git-annex_project vulnerability CVSS: 6.8 20 Aug 2017, 20:29 UTC

git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.