Количество 12
Количество 12

BDU:2025-01510
Уязвимость расширения Git для управления версиями больших файлов Git LFS, связанная с неверной нейтрализацией особых элементов в выходных данных, используемых входящим компонентом, позволяющая нарушителю получить несанкционированный доступ к учетным данным пользователя

CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

CVE-2024-53263
CVE-2024-53263
Git LFS is a Git extension for versioning large files. When Git LFS re ...

openSUSE-SU-2025:0153-1
Security update for git-lfs

RLSA-2025:0845
Important: git-lfs security update
GHSA-q6r2-x2cc-vrp7
Git LFS permits exfiltration of credentials via crafted HTTP URLs
ELSA-2025-0845
ELSA-2025-0845: git-lfs security update (IMPORTANT)
ELSA-2025-0673
ELSA-2025-0673: git-lfs security update (IMPORTANT)

SUSE-SU-2025:0297-1
Security update for govulncheck-vulndb
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2025-01510 Уязвимость расширения Git для управления версиями больших файлов Git LFS, связанная с неверной нейтрализацией особых элементов в выходных данных, используемых входящим компонентом, позволяющая нарушителю получить несанкционированный доступ к учетным данным пользователя | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2024-53263 Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time. | 0% Низкий | 5 месяцев назад | |
![]() | CVE-2024-53263 Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time. | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2024-53263 Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time. | 0% Низкий | 5 месяцев назад | |
![]() | 0% Низкий | 5 месяцев назад | ||
CVE-2024-53263 Git LFS is a Git extension for versioning large files. When Git LFS re ... | 0% Низкий | 5 месяцев назад | ||
![]() | openSUSE-SU-2025:0153-1 Security update for git-lfs | 0% Низкий | около 1 месяца назад | |
![]() | RLSA-2025:0845 Important: git-lfs security update | 0% Низкий | 4 месяца назад | |
GHSA-q6r2-x2cc-vrp7 Git LFS permits exfiltration of credentials via crafted HTTP URLs | 0% Низкий | 5 месяцев назад | ||
ELSA-2025-0845 ELSA-2025-0845: git-lfs security update (IMPORTANT) | 5 месяцев назад | |||
ELSA-2025-0673 ELSA-2025-0673: git-lfs security update (IMPORTANT) | 5 месяцев назад | |||
![]() | SUSE-SU-2025:0297-1 Security update for govulncheck-vulndb | 5 месяцев назад |
Уязвимостей на страницу