CVE-2020-5260| GitÊäÈëÑéÖ¤¹ýʧÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-170x00 Îó²î¸ÅÊö
|
CVE ID |
CVE-2020-5260 |
ʱ ¼ä |
2020-04-17 |
|
Àà ÐÍ |
IVE |
µÈ ¼¶ |
ÑÏÖØ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
Git 2.17.x <= 2.17.3 Git 2.18.x <= 2.18.2 Git 2.19.x <= 2.19.3 Git 2.20.x <= 2.20.2 Git 2.21.x <= 2.21.1 Git 2.22.x <= 2.22.2 Git 2.23.x <= 2.23.1 Git 2.24.x <= 2.24.1 Git 2.25.x <= 2.25.2 Git 2.26.x <= 2.26.0 |
0x01 Îó²îÏêÇé
GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÂþÑÜʽ°æ±¾¿ØÖÆÏµÍ³£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¿ìËÙ¸ßЧµØ´¦Öóͷ£´ÓСÐ͵½´óÐÍÏîÄ¿µÄËùÓÐÄÚÈÝ¡£¡£¡£¡£¡£
4ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬GitÐû²¼ÁËÒ»¸öÊäÈëÑéÖ¤¹ýʧÎó²î£¨CVE-2020-5260£©,¸ÃÎó²î»áµ¼ÖÂGitÓû§Æ¾Ö¤Ð¹Â¶¡£¡£¡£¡£¡£
GitʹÓÃÆ¾Ö¤ÖúÊÖ(credential helper)À´×ÊÖúÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£¡£¡£¡£¡£µ±URLÖаüÀ¨¾ÓɱàÂëµÄ»»Ðзû£¨%0a£©Ê±£¬£¬£¬£¬£¬£¬£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄÐÒéÁ÷ÖС£¡£¡£¡£¡£µ¼ÖÂÆ¾Ö¤ÖúÊÖ¼ìË÷Ò»¸öЧÀÍÆ÷µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬ÏòÁíÒ»¸öЧÀÍÆ÷·¢³öHTTPÇëÇ󣬣¬£¬£¬£¬£¬£¬Ê¹Ç°Õߵį¾Ö¤·¢Ë͵½ºóÕߣ¬£¬£¬£¬£¬£¬£¬²¢ÇÒÁ½ÕßÖ®¼äµÄ¹ØÏµÃ»ÓÐÈκÎÏÞÖÆ¡£¡£¡£¡£¡£ÕâÒâζ׏¥»÷Õß¿ÉÒÔÖÆ×÷Ò»¸öURL£¬£¬£¬£¬£¬£¬£¬¸ÃURL½«ÏòÆäÑ¡ÔñµÄÖ÷»úÌṩÈκÎÖ÷»úµÄ´æ´¢Æ¾Ö¤¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ÏÂÁîʱ»á´¥·¢´ËÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâURLÓÕÆGit¿Í»§¶Ë·¢ËÍÖ÷»úƾ֤¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Éý¼¶²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://github.com/git/git/releases
ÔÝʱ²½·¥£º
½ûÓÃcredential helper£º
git config --unset credential.helper
git config --global --unset credential.helper
git config --system --unset credential.helper
×èÖ¹¶ñÒâURL:
1. git cloneʱ¼ì²éURLµÄÖ÷»úÃûºÍÓû§Ãû²¿·ÖÊÇ·ñ±£´æ±àÂëµÄ»»Ðзû£¨%0a£©»òƾ֤ÐÒé×¢ÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©£»£»£»£»£»£»
2. ×èÖ¹½«×ÓÄ£¿£¿£¿£¿£¿£¿£¿éÓë²»ÊÜÐÅÈεĴ洢¿âÒ»ÆðʹÓ㨲»ÒªÊ¹ÓÃclone --recurse-submodules£»£»£»£»£»£»½öÔÚ¼ì²é.gitmodulesÖеÄURLÖ®ºó²ÅʹÓÃgit×ÓÄ£¿£¿£¿£¿£¿£¿£¿é¸üУ©£»£»£»£»£»£»
3. ×èÖ¹¶Ô²»ÐÅÈεÄURLÖ´ÐÐ git clone¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.suse.com/security/cve/CVE-2020-5260/
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-5260
https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q
0x05 ʱ¼äÏß
2020-04-14 GitÐû²¼Í¨¸æ
2020-04-14 CVEÐû²¼¸ÃÎó²î


¾©¹«Íø°²±¸11010802024551ºÅ