CVE-2020-5260| GitÊäÈëÑéÖ¤¹ýʧÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-17

0x00 Îó²î¸ÅÊö


CVE   ID

CVE-2020-5260

ʱ    ¼ä

2020-04-17

Àà    ÐÍ

IVE

µÈ    ¼¶

ÑÏÖØ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

Git 2.17.x <= 2.17.3

Git 2.18.x <= 2.18.2

Git 2.19.x <= 2.19.3

Git 2.20.x <= 2.20.2

Git 2.21.x <= 2.21.1

Git 2.22.x <= 2.22.2

Git 2.23.x <= 2.23.1

Git 2.24.x <= 2.24.1

Git 2.25.x <= 2.25.2

Git 2.26.x <= 2.26.0


0x01 Îó²îÏêÇé

Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£



GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÂþÑÜʽ°æ±¾¿ØÖÆÏµÍ³£¬Ö¼ÔÚ¿ìËÙ¸ßЧµØ´¦Öóͷ£´ÓСÐ͵½´óÐÍÏîÄ¿µÄËùÓÐÄÚÈÝ¡£


4ÔÂ14ÈÕ£¬GitÐû²¼ÁËÒ»¸öÊäÈëÑéÖ¤¹ýʧÎó²î£¨CVE-2020-5260£©,¸ÃÎó²î»áµ¼ÖÂGitÓû§Æ¾Ö¤Ð¹Â¶¡£


GitʹÓÃÆ¾Ö¤ÖúÊÖ(credential helper)À´×ÊÖúÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£µ±URLÖаüÀ¨¾­ÓɱàÂëµÄ»»Ðзû£¨%0a£©Ê±£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄЭÒéÁ÷ÖС£µ¼ÖÂÆ¾Ö¤ÖúÊÖ¼ìË÷Ò»¸ö·þÎñÆ÷µÄÃÜÂ룬ÏòÁíÒ»¸ö·þÎñÆ÷·¢³öHTTPÇëÇó£¬Ê¹Ç°Õߵį¾Ö¤·¢Ë͵½ºóÕߣ¬²¢ÇÒÁ½ÕßÖ®¼äµÄ¹ØÏµÃ»ÓÐÈκÎÏÞÖÆ¡£ÕâÒâζ׏¥»÷Õß¿ÉÒÔÖÆ×÷Ò»¸öURL£¬¸ÃURL½«ÏòÆäÑ¡ÔñµÄÖ÷»úÌṩÈκÎÖ÷»úµÄ´æ´¢Æ¾Ö¤¡£ÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ÏÂÁîʱ»á´¥·¢´ËÎó²î£¬¹¥»÷Õß¿ÉʹÓöñÒâURLÓÕÆ­Git¿Í»§¶Ë·¢ËÍÖ÷»úƾ֤¡£


0x02 ´¦Öóͷ£½¨Òé


Éý¼¶²¹¶¡£¬ÏÂÔØÁ´½Ó£º

https://github.com/git/git/releases


ÔÝʱ²½·¥£º


½ûÓÃcredential helper£º

git config --unset credential.helper

git config --global --unset credential.helper

git config --system --unset credential.helper


×èÖ¹¶ñÒâURL:

1. git cloneʱ¼ì²éURLµÄÖ÷»úÃûºÍÓû§Ãû²¿·ÖÊÇ·ñ±£´æ±àÂëµÄ»»Ðзû£¨%0a£©»òƾ֤ЭÒé×¢ÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©£»

2. ×èÖ¹½«×ÓÄ£¿éÓë²»ÊÜÐÅÈεĴ洢¿âÒ»ÆðʹÓ㨲»ÒªÊ¹ÓÃclone --recurse-submodules£»½öÔÚ¼ì²é.gitmodulesÖеÄURLÖ®ºó²ÅʹÓÃgit×ÓÄ£¿é¸üУ©£»

3. ×èÖ¹¶Ô²»ÐÅÈεÄURLÖ´ÐÐ git clone¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.suse.com/security/cve/CVE-2020-5260/


0x04 ²Î¿¼Á´½Ó


https://nvd.nist.gov/vuln/detail/CVE-2020-5260

https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q


0x05 ʱ¼äÏß


2020-04-14 GitÐû²¼Í¨¸æ

2020-04-14 CVEÐû²¼¸ÃÎó²î