Логотип exploitDog
bind:CVE-2020-11008
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11008

Количество 10

Количество 10

ubuntu логотип

CVE-2020-11008

почти 6 лет назад

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through sy...

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2020-11008

почти 6 лет назад

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through sy...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-11008

почти 6 лет назад

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through syste

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2020-11008

почти 6 лет назад

Affected versions of Git have a vulnerability whereby Git can be trick ...

CVSS3: 4
EPSS: Низкий
oracle-oval логотип

ELSA-2020-2337

больше 5 лет назад

ELSA-2020-2337: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-1980

почти 6 лет назад

ELSA-2020-1980: git security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-01904

почти 6 лет назад

Уязвимость компонента «credential.helper» распределенной системы управления версиями Git, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1295-1

больше 5 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0598-1

почти 6 лет назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1121-1

почти 6 лет назад

Security update for git

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through sy...

CVSS3: 4
2%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through sy...

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through syste

CVSS3: 4
2%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-11008

Affected versions of Git have a vulnerability whereby Git can be trick ...

CVSS3: 4
2%
Низкий
почти 6 лет назад
oracle-oval логотип
ELSA-2020-2337

ELSA-2020-2337: git security update (IMPORTANT)

больше 5 лет назад
oracle-oval логотип
ELSA-2020-1980

ELSA-2020-1980: git security update (IMPORTANT)

почти 6 лет назад
fstec логотип
BDU:2020-01904

Уязвимость компонента «credential.helper» распределенной системы управления версиями Git, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
2%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1295-1

Security update for git

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0598-1

Security update for git

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1121-1

Security update for git

почти 6 лет назад

Уязвимостей на страницу