Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git's "store" helper - Git's "cache" helper - the "osxkeychain" helper that ships in Git's "contrib" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Jun 11, 2020 | Apr 21, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-daemonUpgrade git-emailUpgrade git-instawebUpgrade git-p4Upgrade gitkUpgrade git-coreUpgrade git-guiUpgrade perl-Git-SVNUpgrade git-debuginfoUpgrade git-allUpgrade git-svnUpgrade perl-GitUpgrade git-cvsUpgrade git-core-docUpgrade gitwebUpgrade gitUpgrade git-subtree | May 8, 2020 | Apr 21, 2020 |
| Amazon_linux | — | Upgrade git | Jul 30, 2020 | Apr 21, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 21, 2020 |
| Centos_linux | — | Upgrade perl-GitUpgrade emacs-git-elUpgrade git-p4Upgrade git-core-docUpgrade git-core-debuginfoUpgrade git-instawebUpgrade gitwebUpgrade git-allUpgrade git-guiUpgrade git-daemonUpgrade git-bzrUpgrade git-coreUpgrade emacs-gitUpgrade git-emailUpgrade git-debuginfoUpgrade git-cvsUpgrade git-subtreeUpgrade perl-Git-SVNUpgrade git-hgUpgrade git-svn-debuginfoUpgrade git-daemon-debuginfoUpgrade git-svnUpgrade gitkUpgrade git-debugsourceUpgrade gitUpgrade git-gnome-keyring | May 1, 2020 | Apr 21, 2020 |
| Debian | — | Upgrade git | Apr 22, 2020 | Apr 22, 2020 |
| Freebsd | — | Upgrade gitlab-ceUpgrade git-liteUpgrade gitUpgrade git-gui | May 2, 2020 | Apr 22, 2020 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Apr 24, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Feb 22, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Jan 20, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade gitUpgrade git-core-docUpgrade git-core | Jun 3, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | May 27, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade gitUpgrade git-help | Sep 29, 2021 | Apr 21, 2020 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.5-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Apr 21, 2020 |
| Oracle_linux | — | Upgrade git-allUpgrade git-svnUpgrade git-cvsUpgrade git-daemonUpgrade git-instawebUpgrade git-guiUpgrade perl-GitUpgrade git-coreUpgrade git-gnome-keyringUpgrade git-bzrUpgrade gitUpgrade git-core-docUpgrade perl-Git-SVNUpgrade gitwebUpgrade git-hgUpgrade git-emailUpgrade gitkUpgrade git-subtreeUpgrade git-p4Upgrade emacs-git-elUpgrade emacs-git | May 29, 2020 | Apr 20, 2020 |
| Redhat_linux | — | Upgrade git-svn-debuginfoUpgrade git-gnome-keyringUpgrade git-svnUpgrade git-instawebUpgrade git-daemon-debuginfoUpgrade git-coreUpgrade git-guiUpgrade git-debugsourceUpgrade git-bzrUpgrade perl-Git-SVNUpgrade git-subtreeUpgrade git-daemonUpgrade emacs-git-elUpgrade gitwebUpgrade git-allUpgrade git-core-docUpgrade git-emailUpgrade perl-GitUpgrade git-hgUpgrade gitUpgrade git-debuginfoUpgrade gitkUpgrade git-cvsUpgrade emacs-gitUpgrade git-p4Upgrade git-core-debuginfo | May 1, 2020 | Apr 21, 2020 |
| Suse | — | Upgrade gitkUpgrade git-coreUpgrade git-p4Upgrade git-guiUpgrade git-docUpgrade git-emailUpgrade git-daemonUpgrade git-credential-gnome-keyringUpgrade git-credential-libsecretUpgrade git-cvsUpgrade git-webUpgrade gitUpgrade git-archUpgrade git-svn | May 7, 2020 | Apr 21, 2020 |
| Ubuntu | — | Upgrade git | Apr 22, 2020 | Apr 21, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub