CVE-2020-5260| GitÊäÈëÑéÖ¤ÃýÎó·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-170x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-5260 |
ʱ ¼ä |
2020-04-17 |
|
Àà ÐÍ |
IVE |
µÈ ¼¶ |
ÑϳÁ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Git 2.17.x <= 2.17.3 Git 2.18.x <= 2.18.2 Git 2.19.x <= 2.19.3 Git 2.20.x <= 2.20.2 Git 2.21.x <= 2.21.1 Git 2.22.x <= 2.22.2 Git 2.23.x <= 2.23.1 Git 2.24.x <= 2.24.1 Git 2.25.x <= 2.25.2 Git 2.26.x <= 2.26.0 |
0x01 ·ì϶ÏêÇé
GitÊÇÒ»Ì×Ãâ·Ñ¡¢¿ªÔ´µÄÉ¢²¼Ê½°æ±¾½ÚÔìϵͳ£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼±¾ç¸ßЧµØ´¦ÖôÓÓ×Ð͵½´óÐÍÏîÖ÷ÕÅËùÓÐÄÚÈÝ¡£¡£¡£¡£¡£
4ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬Git°ä²¼ÁËÒ»¸öÊäÈëÑéÖ¤ÃýÎó·ì϶£¨CVE-2020-5260£©,¸Ã·ì϶»áµ¼ÖÂGitÓû§Æ¾Ö¤Ð¹Â¶¡£¡£¡£¡£¡£
GitʹÓÃÆ¾Ö¤¸±ÊÖ(credential helper)À´Ô®ÊÖÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£¡£¡£¡£¡£µ±URLÖÐÔ̺¬¾¹ý±àÂëµÄ»»Ðзû£¨%0a£©Ê±£¬£¬£¬£¬£¬£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄºÍ̸Á÷ÖÓ×£¡£¡£¡£¡£µ¼ÖÂÆ¾Ö¤¸±ÊÖ¼ìË÷Ò»¸ö·þÎñÆ÷µÄÃÜÂ룬£¬£¬£¬£¬£¬ÏòÁíÒ»¸ö·þÎñÆ÷·¢³öHTTPÒªÇ󣬣¬£¬£¬£¬£¬Ê¹Ç°ÕßµÄÍ´´¦·¢Ë͵½ºóÕߣ¬£¬£¬£¬£¬£¬²¢ÇÒÁ½ÕßÖ®¼äµÄ¹ØÏµÃ»ÓÐÈκÎÏÞ¶È¡£¡£¡£¡£¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Ôì×÷Ò»¸öURL£¬£¬£¬£¬£¬£¬¸ÃURL½«ÏòÆäÑ¡ÔñµÄÖ÷»úÌṩÈκÎÖ÷»úµÄ´æ´¢Í´´¦¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ºÅÁîʱ»á´¥·¢´Ë·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓöñÒâURLºýŪGit¿Í»§¶Ë·¢ËÍÖ÷»úÍ´´¦¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Éý¼¶²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://github.com/git/git/releases
һʱ´ëÊ©£º
½ûÓÃcredential helper£º
git config --unset credential.helper
git config --global --unset credential.helper
git config --system --unset credential.helper
Ô¤·À¶ñÒâURL:
1. git cloneʱ²é³URLµÄÖ÷»úÃûºÍÓû§Ãû²¿ÃÅÊÇ·ñ´æÔÚ±àÂëµÄ»»Ðзû£¨%0a£©»òÍ´´¦ºÍ̸עÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©£»£»£»£»£»
2. Ô¤·À½«×ÓÄ£¿£¿£¿£¿£¿£¿éÓë²»ÊÜÐÅÀµµÄ´æ´¢¿âһ·ʹÓ㨲»ÒªÊ¹ÓÃclone --recurse-submodules£»£»£»£»£»½öÔÚ²é³.gitmodulesÖеÄURLÖ®ºó²ÅʹÓÃgit×ÓÄ£¿£¿£¿£¿£¿£¿é¸üУ©£»£»£»£»£»
3. Ô¤·À¶Ô²»ÐÅÀµµÄURLÖ´ÐÐ git clone¡£¡£¡£¡£¡£
0x03 ÓйØÐÂÎÅ
https://www.suse.com/security/cve/CVE-2020-5260/
0x04 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2020-5260
https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q
0x05 ¹¦·òÏß
2020-04-14 Git°ä²¼²¼¸æ
2020-04-14 CVE°ä²¼¸Ã·ì϶


¾©¹«Íø°²±¸11010802024551ºÅ