Bug 2337824 (CVE-2024-50349)
| Summary: | CVE-2024-50349 git: Git does not sanitize URLs when asking for credentials interactively | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | adudiak, chazlett, crizzo, dfreiber, drow, gmalinko, janstey, jburrell, jmitchel, jtanner, kshier, omaciel, pdelbell, rstepani, stcannon, vkumar, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in Git. This vulnerability occurs when Git requests credentials via a terminal prompt, for example, without the use of a credential helper. During this process, Git displays the host name for which the credentials are needed, but any URL-encoded parts are decoded and displayed directly. This can allow an attacker to manipulate URLs by including ANSI escape sequences, which can be interpreted by the terminal to mislead users by tricking them into entering passwords that are redirected to malicious attacker-controlled sites.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-01-14 19:01:23 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:11462 https://access.redhat.com/errata/RHSA-2025:11462 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:11533 https://access.redhat.com/errata/RHSA-2025:11533 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:11534 https://access.redhat.com/errata/RHSA-2025:11534 This issue has been addressed in the following products: RHEL-8 based Middleware Containers Via RHSA-2025:13276 https://access.redhat.com/errata/RHSA-2025:13276 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:19601 https://access.redhat.com/errata/RHSA-2025:19601 |