CVE-2020-5260| GitÊäÈëÑéÖ¤ÃýÎó·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-170x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-5260 |
ʱ ¼ä |
2020-04-17 |
|
Àà ÐÍ |
IVE |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Git 2.17.x <= 2.17.3 Git 2.18.x <= 2.18.2 Git 2.19.x <= 2.19.3 Git 2.20.x <= 2.20.2 Git 2.21.x <= 2.21.1 Git 2.22.x <= 2.22.2 Git 2.23.x <= 2.23.1 Git 2.24.x <= 2.24.1 Git 2.25.x <= 2.25.2 Git 2.26.x <= 2.26.0 |
0x01 ·ì϶ÏêÇé
GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÉ¢²¼Ê½°æ±¾½ÚÔìϵͳ£¬Ö¼ÔÚ¼±¾ç¸ßЧµØ´¦ÖôÓÓ×Ð͵½´óÐÍÏîÖ÷ÕÅËùÓÐÄÚÈÝ¡£
4ÔÂ14ÈÕ£¬Git°ä²¼ÁËÒ»¸öÊäÈëÑéÖ¤ÃýÎó·ì϶£¨CVE-2020-5260£©,¸Ã·ì϶»áµ¼ÖÂGitÓû§Æ¾Ö¤Ð¹Â¶¡£
GitʹÓÃÆ¾Ö¤¸±ÊÖ(credential helper)À´Ô®ÊÖÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£µ±URLÖÐÔ̺¬¾¹ý±àÂëµÄ»»Ðзû£¨%0a£©Ê±£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄºÍ̸Á÷ÖС£µ¼ÖÂÆ¾Ö¤¸±ÊÖ¼ìË÷Ò»¸ö·þÎñÆ÷µÄÃÜÂ룬ÏòÁíÒ»¸ö·þÎñÆ÷·¢³öHTTPÒªÇó£¬Ê¹Ç°ÕßµÄÍ´´¦·¢Ë͵½ºóÕߣ¬²¢ÇÒÁ½ÕßÖ®¼äµÄ¹ØÏµÃ»ÓÐÈκÎÏÞ¶È¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Ôì×÷Ò»¸öURL£¬¸ÃURL½«ÏòÆäÑ¡ÔñµÄÖ÷»úÌṩÈκÎÖ÷»úµÄ´æ´¢Í´´¦¡£ÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ºÅÁîʱ»á´¥·¢´Ë·ì϶£¬¹¥»÷Õß¿ÉÀûÓöñÒâURLºýŪGit¿Í»§¶Ë·¢ËÍÖ÷»úÍ´´¦¡£
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º
https://github.com/git/git/releases
һʱ´ëÊ©£º
½ûÓÃcredential helper£º
git config --unset credential.helper
git config --global --unset credential.helper
git config --system --unset credential.helper
Ô¤·À¶ñÒâURL:
1. git cloneʱ²é³URLµÄÖ÷»úÃûºÍÓû§Ãû²¿ÃÅÊÇ·ñ´æÔÚ±àÂëµÄ»»Ðзû£¨%0a£©»òÍ´´¦ºÍ̸עÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©£»
2. Ô¤·À½«×ÓÄ£¿éÓë²»ÊÜÐÅÀµµÄ´æ´¢¿âһ·ʹÓ㨲»ÒªÊ¹ÓÃclone --recurse-submodules£»½öÔÚ²é³.gitmodulesÖеÄURLÖ®ºó²ÅʹÓÃgit×ÓÄ£¿é¸üУ©£»
3. Ô¤·À¶Ô²»ÐÅÀµµÄURLÖ´ÐÐ git clone¡£
0x03 ÓйØÐÂÎÅ
https://www.suse.com/security/cve/CVE-2020-5260/
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-5260
https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q
0x05 ¹¦·òÏß
2020-04-14 Git°ä²¼²¼¸æ
2020-04-14 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ