Disclosure Date 2021/01/07

CVE-2021-40330

Server-Side Request Forgery (SSRF) vulnerability in git

gitにおけるSSRF(サーバサイドリクエストフォージェリ)

Credit

stypr (@stereotype32)

Affected-Versions

v2.30.0 and earlier

CWE

CWE-918

Description

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated in the git commit

Back