git_connect_git in connect.c in Git... CVE-2021-40330

5.0 AV AC AU C I A
发布: 2021-08-31
修订: 2024-11-21

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息