Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-40330

Опубликовано: 07 янв. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

A flaw was found in git where it allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring. The highest threat from this vulnerability is to confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12gitNot affected
Red Hat Enterprise Linux 7gitOut of support scope
Red Hat Enterprise Linux 8gitNot affected
Red Hat Enterprise Linux 9gitNot affected
Red Hat Software Collectionsrh-git227-gitWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1999755git: unexpected cross-protocol requests via a repository path containing a newline character

EPSS

Процентиль: 63%
0.00447
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

CVSS3: 7.5
nvd
больше 4 лет назад

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

git_connect_git in connect.c in Git before 2.30.1 allows a repository ...

suse-cvrf
больше 4 лет назад

Security update for git

EPSS

Процентиль: 63%
0.00447
Низкий

7.5 High

CVSS3