Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24975

Опубликовано: 11 фев. 2022
Источник: redhat
CVSS3: 7.5

Описание

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

A flaw known as "GitBleed" was found in Git, where repositories cloned via the "–mirror" option may leak secrets or sensitive information if not properly removed/deleted earlier. This flaw allows attackers and bug bounty hunters to use this discrepancy in Git behavior to find hidden secrets and other sensitive data in public repositories.

Отчет

The "GitBleed" issue can't be fixed, because it requires basic user education and can be fixed only by administrators responsible for individual repositories by analyzing a whole copy of their own repositories using the “–mirror” option and removing sensitive data using tools like BFG or git-filter-repo.

Меры по смягчению последствий

Organizations can mitigate this by analyzing a fuller copy of their repositories using the “–mirror” option and removing sensitive data using tools like BFG or git-filter-repo. Garbage collection and pruning in git is also recommended. Organizations should not analyze regular cloned copies (without the “–mirror” option) since that may provide a false sense of security, and should not rely on methods of removing secrets such as deleting a branch or rewinding history via the “git reset” command.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12gitNot affected
Red Hat Enterprise Linux 7gitNot affected
Red Hat Enterprise Linux 8gitNot affected
Red Hat Enterprise Linux 9gitNot affected
Red Hat Software Collectionsrh-git227-gitNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2054686git: The --mirror option for git leaks secret for deleted content, aka the "GitBleed"

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

CVSS3: 7.5
nvd
почти 4 года назад

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

CVSS3: 7.5
debian
почти 4 года назад

The --mirror documentation for Git through 2.35.1 does not mention the ...

CVSS3: 7.5
github
почти 4 года назад

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option.

CVSS3: 5.9
fstec
почти 4 года назад

Уязвимость распределенной системы управления версиями Git, связанная с раскрытием информации в ошибочной области данных, позволяющая нарушителю получить доступ к конфиденциальным данным

7.5 High

CVSS3