PT-2021-8149 · Git+5 · Git+5
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Git versions prior to 2.30.1
Description
The issue is related to the git connect git function in the connect.c component of the Git distributed version control system. It allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests. This is demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.
Recommendations
For Git versions prior to 2.30.1, update to version 2.30.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the git connect git function in the connect.c component until a patch is available. Avoid using repository paths that contain newline characters in the affected API endpoint until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Git
Linuxmint
Suse
Ubuntu