CVE-2020-5260| GitÊäÈëÑéÖ¤ÃýÎó·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-17

0x00 ·ì϶¸ÅÊö


CVE   ID

CVE-2020-5260

ʱ    ¼ä

2020-04-17

Àà    ÐÍ

IVE

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Git 2.17.x <= 2.17.3

Git 2.18.x <= 2.18.2

Git 2.19.x <= 2.19.3

Git 2.20.x <= 2.20.2

Git 2.21.x <= 2.21.1

Git 2.22.x <= 2.22.2

Git 2.23.x <= 2.23.1

Git 2.24.x <= 2.24.1

Git 2.25.x <= 2.25.2

Git 2.26.x <= 2.26.0


0x01 ·ì϶ÏêÇé

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÉ¢²¼Ê½°æ±¾½ÚÔìϵͳ£¬Ö¼ÔÚ¼±¾ç¸ßЧµØ´¦ÖôÓÓ×Ð͵½´óÐÍÏîÖ÷ÕÅËùÓÐÄÚÈÝ¡£


4ÔÂ14ÈÕ£¬Git°ä²¼ÁËÒ»¸öÊäÈëÑéÖ¤ÃýÎó·ì϶£¨CVE-2020-5260£©,¸Ã·ì϶»áµ¼ÖÂGitÓû§Æ¾Ö¤Ð¹Â¶¡£


GitʹÓÃÆ¾Ö¤¸±ÊÖ(credential helper)À´Ô®ÊÖÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£µ±URLÖÐÔ̺¬¾­¹ý±àÂëµÄ»»Ðзû£¨%0a£©Ê±£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄºÍ̸Á÷ÖС£µ¼ÖÂÆ¾Ö¤¸±ÊÖ¼ìË÷Ò»¸ö·þÎñÆ÷µÄÃÜÂ룬ÏòÁíÒ»¸ö·þÎñÆ÷·¢³öHTTPÒªÇó£¬Ê¹Ç°ÕßµÄÍ´´¦·¢Ë͵½ºóÕߣ¬²¢ÇÒÁ½ÕßÖ®¼äµÄ¹ØÏµÃ»ÓÐÈκÎÏÞ¶È¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Ôì×÷Ò»¸öURL£¬¸ÃURL½«ÏòÆäÑ¡ÔñµÄÖ÷»úÌṩÈκÎÖ÷»úµÄ´æ´¢Í´´¦¡£ÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ºÅÁîʱ»á´¥·¢´Ë·ì϶£¬¹¥»÷Õß¿ÉÀûÓöñÒâURLºýŪGit¿Í»§¶Ë·¢ËÍÖ÷»úÍ´´¦¡£


0x02 ´ëÖý¨Òé


Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://github.com/git/git/releases


һʱ´ëÊ©£º


½ûÓÃcredential helper£º

git config --unset credential.helper

git config --global --unset credential.helper

git config --system --unset credential.helper


Ô¤·À¶ñÒâURL:

1. git cloneʱ²é³­URLµÄÖ÷»úÃûºÍÓû§Ãû²¿ÃÅÊÇ·ñ´æÔÚ±àÂëµÄ»»Ðзû£¨%0a£©»òÍ´´¦ºÍ̸עÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©£»

2. Ô¤·À½«×ÓÄ £¿éÓë²»ÊÜÐÅÀµµÄ´æ´¢¿âһ·ʹÓ㨲»ÒªÊ¹ÓÃclone --recurse-submodules£»½öÔڲ鳭.gitmodulesÖеÄURLÖ®ºó²ÅʹÓÃgit×ÓÄ £¿é¸üУ©£»

3. Ô¤·À¶Ô²»ÐÅÀµµÄURLÖ´ÐÐ git clone¡£


0x03 ÓйØÐÂÎÅ


https://www.suse.com/security/cve/CVE-2020-5260/


0x04 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2020-5260

https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q


0x05 ¹¦·òÏß


2020-04-14 Git°ä²¼²¼¸æ

2020-04-14 CVE°ä²¼¸Ã·ì϶