CVE-2024-53263
Git LFS permits exfiltration of credentials via crafted HTTP URLs
描述
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.
如何修補 CVE-2024-53263
要修補 CVE-2024-53263,請將受影響套件升級到下列已修補版本。
- —升級至 3.6.1 或更新版本
- —升級至 2.13.2-1+deb11u1 或更新版本
- —升級至 2.13.2-1+deb11u1 或更新版本
- —升級至 3.3.0-1+deb12u1 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 3.6.1 或更新版本
- —升級至 3.6.1 或更新版本
CVE-2024-53263 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(8)
- >= 0.1.0, < 3.6.1
- from 0, < 2.13.2-1+deb11u1
- from 0, < 2.13.2-1+deb11u1
- from 0, < 3.3.0-1+deb12u1
- >= 0.1.0, <= 3.0.0
- >= 0.1.0
- >= 3.0.0, < 3.6.1
- >= 3.0.0, < 3.6.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |