Логотип exploitDog
bind:"GHSA-q6r2-x2cc-vrp7" OR bind:"CVE-2024-53263"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-q6r2-x2cc-vrp7" OR bind:"CVE-2024-53263"

Количество 12

Количество 12

github логотип

GHSA-q6r2-x2cc-vrp7

5 месяцев назад

Git LFS permits exfiltration of credentials via crafted HTTP URLs

EPSS: Низкий
ubuntu логотип

CVE-2024-53263

5 месяцев назад

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

EPSS: Низкий
redhat логотип

CVE-2024-53263

5 месяцев назад

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-53263

5 месяцев назад

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

EPSS: Низкий
msrc логотип

CVE-2024-53263

5 месяцев назад

EPSS: Низкий
debian логотип

CVE-2024-53263

5 месяцев назад

Git LFS is a Git extension for versioning large files. When Git LFS re ...

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0153-1

около 1 месяца назад

Security update for git-lfs

EPSS: Низкий
rocky логотип

RLSA-2025:0845

4 месяца назад

Important: git-lfs security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0845

5 месяцев назад

ELSA-2025-0845: git-lfs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-0673

5 месяцев назад

ELSA-2025-0673: git-lfs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-01510

5 месяцев назад

Уязвимость расширения Git для управления версиями больших файлов Git LFS, связанная с неверной нейтрализацией особых элементов в выходных данных, используемых входящим компонентом, позволяющая нарушителю получить несанкционированный доступ к учетным данным пользователя

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0297-1

5 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q6r2-x2cc-vrp7

Git LFS permits exfiltration of credentials via crafted HTTP URLs

0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2024-53263

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

0%
Низкий
5 месяцев назад
redhat логотип
CVE-2024-53263

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2024-53263

Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.

0%
Низкий
5 месяцев назад
msrc логотип
0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-53263

Git LFS is a Git extension for versioning large files. When Git LFS re ...

0%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:0153-1

Security update for git-lfs

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2025:0845

Important: git-lfs security update

0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2025-0845

ELSA-2025-0845: git-lfs security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2025-0673

ELSA-2025-0673: git-lfs security update (IMPORTANT)

5 месяцев назад
fstec логотип
BDU:2025-01510

Уязвимость расширения Git для управления версиями больших файлов Git LFS, связанная с неверной нейтрализацией особых элементов в выходных данных, используемых входящим компонентом, позволяющая нарушителю получить несанкционированный доступ к учетным данным пользователя

CVSS3: 8.8
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0297-1

Security update for govulncheck-vulndb

5 месяцев назад

Уязвимостей на страницу