Disclosure Date 2021/01/07
CVE-2021-40330
Server-Side Request Forgery (SSRF) vulnerability in git
git における SSRF (サーバサイドリクエストフォージェリ)
Credit
stypr (@stereotype32)
Affected-Versions
Git: v2.30.0 and earlier
CWE
- CWE-918
Description
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated in the git commit