Credential Exposure in Git by Attacker-Controlled URLs
CVE-2024-50349
What is CVE-2024-50349?
A vulnerability in Git allows attackers to exploit the credential prompt by using specially crafted URLs with ANSI escape sequences. When users enter credentials via the terminal without a credential helper, the hostname displayed can mislead users into providing sensitive information to an untrusted site. This flaw has been addressed in the latest Git releases, and users are strongly encouraged to update their software to avoid potential credential leaks. For those unable to upgrade, it is crucial to refrain from cloning from untrusted URLs, particularly in recursive clones.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
git <= 2.40.3 <= 2.40.3
git >= 2.41.0, <= 2.41.2 <= 2.41.0, 2.41.2
git >= 2.42.0, <= 2.42.3 <= 2.42.0, 2.42.3
References
CVSS V4
Timeline
Vulnerability published
