CVE-2024-53263
CVSS V2 None
CVSS V3 None
Description
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters such as line feed (LF) or carriage return (CR) characters into the URL, an attacker may be able to retrieve a user's Git credentials. This problem exists in all previous versions and is patched in v3.6.1. All users should upgrade to v3.6.1. There are no workarounds known at this time.
Overview
- CVE ID
- CVE-2024-53263
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2025-01-14T19:33:21.876Z
- Last Modified Date
- 2025-01-15T14:55:48.695Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/git-lfs/git-lfs/security/advisories/GHSA-q6r2-x2cc-vrp7 | x_refsource_CONFIRM |
https://github.com/git-lfs/git-lfs/commit/0345b6f816e611d050c0df67b61f0022916a1c90 | x_refsource_MISC |
https://github.com/git-lfs/git-lfs/releases/tag/v3.6.1 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-53263 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53263 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2025-01-16 13:30:25 | Added to TrackCVE |