Disclosure Date 2021/01/07

CVE-2021-40330

Server-Side Request Forgery (SSRF) vulnerability in git

git における SSRF (サーバサイドリクエストフォージェリ)

Credit

stypr (@stereotype32)

Affected-Versions

Git: v2.30.0 and earlier

CWE

  • CWE-918

Description

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated in the git commit

Product-URLs

Back