Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git's "store" helper - Git's "cache" helper - the "osxkeychain" helper that ships in Git's "contrib" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Jun 11, 2020 | Apr 21, 2020 |
| Amazon Linux Ami 2 | — | Upgrade perl-Git-SVNUpgrade git-p4Upgrade git-daemonUpgrade git-instawebUpgrade git-emailUpgrade git-guiUpgrade git-coreUpgrade gitkUpgrade git-allUpgrade git-core-docUpgrade git-cvsUpgrade perl-GitUpgrade gitUpgrade gitwebUpgrade git-subtreeUpgrade git-debuginfoUpgrade git-svn | May 8, 2020 | Apr 21, 2020 |
| Amazon_linux | — | Upgrade git | Jul 30, 2020 | Apr 21, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 21, 2020 |
| Centos_linux | — | Upgrade git-guiUpgrade git-instawebUpgrade git-core-debuginfoUpgrade gitwebUpgrade git-daemonUpgrade git-allUpgrade perl-GitUpgrade git-core-docUpgrade emacs-git-elUpgrade git-p4Upgrade git-subtreeUpgrade git-svnUpgrade git-hgUpgrade git-daemon-debuginfoUpgrade git-emailUpgrade gitkUpgrade git-gnome-keyringUpgrade git-cvsUpgrade git-debuginfoUpgrade perl-Git-SVNUpgrade git-debugsourceUpgrade emacs-gitUpgrade gitUpgrade git-bzrUpgrade git-svn-debuginfoUpgrade git-core | May 1, 2020 | Apr 21, 2020 |
| Debian | — | Upgrade git | Apr 22, 2020 | Apr 22, 2020 |
| Freebsd | — | Upgrade gitlab-ceUpgrade git-liteUpgrade gitUpgrade git-gui | May 2, 2020 | Apr 22, 2020 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Apr 24, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Feb 22, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Jan 20, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-coreUpgrade gitUpgrade git-core-doc | Jun 3, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | May 27, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade git-helpUpgrade git | Sep 29, 2021 | Apr 21, 2020 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.5-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Apr 21, 2020 |
| Oracle_linux | — | Upgrade git-daemonUpgrade git-instawebUpgrade git-gnome-keyringUpgrade git-coreUpgrade perl-GitUpgrade git-bzrUpgrade git-guiUpgrade git-svnUpgrade git-allUpgrade git-cvsUpgrade git-hgUpgrade gitwebUpgrade perl-Git-SVNUpgrade emacs-git-elUpgrade git-subtreeUpgrade gitUpgrade gitkUpgrade git-core-docUpgrade emacs-gitUpgrade git-p4Upgrade git-email | May 29, 2020 | Apr 20, 2020 |
| Redhat_linux | — | Upgrade git-daemon-debuginfoUpgrade git-guiUpgrade git-subtreeUpgrade git-coreUpgrade git-svnUpgrade git-instawebUpgrade git-bzrUpgrade git-daemonUpgrade git-svn-debuginfoUpgrade git-gnome-keyringUpgrade git-debugsourceUpgrade perl-Git-SVNUpgrade emacs-git-elUpgrade git-emailUpgrade git-core-debuginfoUpgrade git-allUpgrade gitUpgrade git-p4Upgrade gitkUpgrade git-debuginfoUpgrade git-cvsUpgrade git-core-docUpgrade git-hgUpgrade perl-GitUpgrade emacs-gitUpgrade gitweb | May 1, 2020 | Apr 21, 2020 |
| Suse | — | Upgrade git-credential-gnome-keyringUpgrade gitUpgrade git-credential-libsecretUpgrade git-archUpgrade git-webUpgrade git-cvsUpgrade git-svnUpgrade git-docUpgrade git-p4Upgrade git-guiUpgrade git-coreUpgrade gitkUpgrade git-emailUpgrade git-daemon | May 7, 2020 | Apr 21, 2020 |
| Ubuntu | — | Upgrade git | Apr 22, 2020 | Apr 21, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub