Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that are considered illegal as of the recently published Git versions can cause Git to send a "blank" pattern to helpers, missing hostname and protocol fields. Many helpers will interpret this as matching _any_ URL, and will return some unspecified stored password, leaking the password to an attacker's server. The vulnerability can be triggered by feeding a malicious URL to `git clone`. However, the affected URLs look rather suspicious; the likely vector would be through systems which automatically clone URLs not visible to the user, such as Git submodules, or package systems built around Git. The root of the problem is in Git itself, which should not be feeding blank input to helpers. However, the ability to exploit the vulnerability in practice depends on which helpers are in use. Credential helpers which are known to trigger the vulnerability: - Git's "store" helper - Git's "cache" helper - the "osxkeychain" helper that ships in Git's "contrib" directory Credential helpers which are known to be safe even with vulnerable versions of Git: - Git Credential Manager for Windows Any helper not in this list should be assumed to trigger the vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade git | Jun 11, 2020 | Apr 21, 2020 |
| Amazon Linux Ami 2 | — | Upgrade git-instawebUpgrade git-coreUpgrade git-guiUpgrade git-p4Upgrade git-emailUpgrade git-daemonUpgrade gitkUpgrade perl-Git-SVNUpgrade git-core-docUpgrade gitwebUpgrade gitUpgrade git-subtreeUpgrade git-allUpgrade git-svnUpgrade perl-GitUpgrade git-cvsUpgrade git-debuginfo | May 8, 2020 | Apr 21, 2020 |
| Amazon_linux | — | Upgrade git | Jul 30, 2020 | Apr 21, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 21, 2020 |
| Centos_linux | — | Upgrade git-core-debuginfoUpgrade perl-GitUpgrade git-core-docUpgrade git-instawebUpgrade git-p4Upgrade git-daemonUpgrade git-guiUpgrade gitwebUpgrade git-allUpgrade emacs-git-elUpgrade git-coreUpgrade emacs-gitUpgrade git-debugsourceUpgrade git-bzrUpgrade git-debuginfoUpgrade git-svn-debuginfoUpgrade gitkUpgrade git-gnome-keyringUpgrade git-cvsUpgrade perl-Git-SVNUpgrade git-svnUpgrade git-subtreeUpgrade git-hgUpgrade git-daemon-debuginfoUpgrade git-emailUpgrade git | May 1, 2020 | Apr 21, 2020 |
| Debian | — | Upgrade git | Apr 22, 2020 | Apr 22, 2020 |
| Freebsd | — | Upgrade git-guiUpgrade gitlab-ceUpgrade gitUpgrade git-lite | May 2, 2020 | Apr 22, 2020 |
| Gentoo Linux | — | Upgrade dev-vcs/git. | Apr 24, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade git | Feb 22, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade git | Jan 20, 2021 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade git-coreUpgrade gitUpgrade git-core-doc | Jun 3, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade git-coreUpgrade git-core-docUpgrade git | May 27, 2020 | Apr 21, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade git-helpUpgrade git | Sep 29, 2021 | Apr 21, 2020 |
| Oracle Solaris | — | Upgrade developer/versioning/git to version 2.19.5-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Apr 21, 2020 |
| Oracle_linux | — | Upgrade git-daemonUpgrade git-guiUpgrade git-coreUpgrade git-svnUpgrade git-allUpgrade git-instawebUpgrade git-bzrUpgrade git-cvsUpgrade git-gnome-keyringUpgrade perl-GitUpgrade git-p4Upgrade gitwebUpgrade perl-Git-SVNUpgrade gitUpgrade git-emailUpgrade gitkUpgrade git-hgUpgrade emacs-gitUpgrade git-core-docUpgrade git-subtreeUpgrade emacs-git-el | May 29, 2020 | Apr 20, 2020 |
| Redhat_linux | — | Upgrade git-svnUpgrade git-gnome-keyringUpgrade git-daemonUpgrade git-svn-debuginfoUpgrade git-subtreeUpgrade git-coreUpgrade git-bzrUpgrade perl-Git-SVNUpgrade git-debugsourceUpgrade git-instawebUpgrade git-guiUpgrade git-daemon-debuginfoUpgrade git-hgUpgrade gitwebUpgrade emacs-gitUpgrade git-allUpgrade git-debuginfoUpgrade git-core-docUpgrade emacs-git-elUpgrade perl-GitUpgrade git-cvsUpgrade git-p4Upgrade gitkUpgrade git-core-debuginfoUpgrade gitUpgrade git-email | May 1, 2020 | Apr 21, 2020 |
| Suse | — | Upgrade git-coreUpgrade git-p4Upgrade git-emailUpgrade gitkUpgrade git-guiUpgrade git-docUpgrade git-daemonUpgrade git-svnUpgrade gitUpgrade git-archUpgrade git-credential-gnome-keyringUpgrade git-credential-libsecretUpgrade git-webUpgrade git-cvs | May 7, 2020 | Apr 21, 2020 |
| Ubuntu | — | Upgrade git | Apr 22, 2020 | Apr 21, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub