Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git's "store" helper - Git's "cache" helper - the "osxkeychain" helper that ships in Git's "contrib" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Jun 11, 2020 | Apr 21, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-daemonUpgrade gitkUpgrade perl-Git-SVNUpgrade git-instawebUpgrade git-p4Upgrade git-guiUpgrade git-coreUpgrade git-emailUpgrade git-debuginfoUpgrade perl-GitUpgrade git-cvsUpgrade git-svnUpgrade git-core-docUpgrade git-allUpgrade gitwebUpgrade gitUpgrade git-subtree | May 8, 2020 | Apr 21, 2020 |
| Amazon_linux | — | Upgrade git | Jul 30, 2020 | Apr 21, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 21, 2020 |
| Centos_linux | — | Upgrade gitwebUpgrade git-daemonUpgrade perl-GitUpgrade git-core-debuginfoUpgrade git-guiUpgrade git-instawebUpgrade git-core-docUpgrade emacs-git-elUpgrade git-allUpgrade git-p4Upgrade gitkUpgrade git-svnUpgrade gitUpgrade git-gnome-keyringUpgrade git-daemon-debuginfoUpgrade emacs-gitUpgrade perl-Git-SVNUpgrade git-subtreeUpgrade git-coreUpgrade git-cvsUpgrade git-hgUpgrade git-svn-debuginfoUpgrade git-debuginfoUpgrade git-emailUpgrade git-debugsourceUpgrade git-bzr | May 1, 2020 | Apr 21, 2020 |
| Debian | — | Upgrade git | Apr 22, 2020 | Apr 22, 2020 |
| Freebsd | — | Upgrade gitlab-ceUpgrade gitUpgrade git-liteUpgrade git-gui | May 2, 2020 | Apr 22, 2020 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Apr 24, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Feb 22, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Jan 20, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Jun 3, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gitUpgrade git-coreUpgrade git-core-doc | May 27, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade git-helpUpgrade git | Sep 29, 2021 | Apr 21, 2020 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.5-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Apr 21, 2020 |
| Oracle_linux | — | Upgrade git-allUpgrade git-cvsUpgrade git-daemonUpgrade git-svnUpgrade git-coreUpgrade git-instawebUpgrade git-bzrUpgrade git-guiUpgrade git-gnome-keyringUpgrade perl-GitUpgrade perl-Git-SVNUpgrade git-core-docUpgrade git-hgUpgrade emacs-git-elUpgrade emacs-gitUpgrade gitwebUpgrade gitUpgrade gitkUpgrade git-emailUpgrade git-subtreeUpgrade git-p4 | May 29, 2020 | Apr 20, 2020 |
| Redhat_linux | — | Upgrade git-instawebUpgrade git-svn-debuginfoUpgrade perl-Git-SVNUpgrade git-bzrUpgrade git-subtreeUpgrade git-daemon-debuginfoUpgrade git-guiUpgrade git-gnome-keyringUpgrade git-svnUpgrade git-daemonUpgrade git-debugsourceUpgrade git-coreUpgrade perl-GitUpgrade emacs-gitUpgrade git-emailUpgrade git-core-debuginfoUpgrade gitkUpgrade git-allUpgrade gitUpgrade emacs-git-elUpgrade git-core-docUpgrade git-p4Upgrade git-hgUpgrade git-cvsUpgrade git-debuginfoUpgrade gitweb | May 1, 2020 | Apr 21, 2020 |
| Suse | — | Upgrade git-credential-gnome-keyringUpgrade git-credential-libsecretUpgrade gitUpgrade git-cvsUpgrade git-archUpgrade git-svnUpgrade git-webUpgrade git-daemonUpgrade git-docUpgrade gitkUpgrade git-p4Upgrade git-coreUpgrade git-emailUpgrade git-gui | May 7, 2020 | Apr 21, 2020 |
| Ubuntu | — | Upgrade git | Apr 22, 2020 | Apr 21, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub