CVE-2021-40330: High severity git-scm Git vulnerability
Published Aug 31, 2021
·Updated
gitconnectgit in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.
Affected Software
2 affected components
git-scm Git<2.30.1
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Aug 31, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2021-40330.
2
What is the severity of CVE-2021-40330?
The severity of CVE-2021-40330 is high with a CVSS score of 7.5.
3
What is the affected software for CVE-2021-40330?
The affected software for CVE-2021-40330 is Git before version 2.30.1 and Debian Linux 10.0.
4
What is the impact of CVE-2021-40330?
CVE-2021-40330 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests.
5
How can I fix CVE-2021-40330?
To fix CVE-2021-40330, update Git to version 2.30.1 or apply the patch provided by the vendor.