Git Gets Patched for Newly Found FlawGit Gets Patched for Newly Found Flaw
A vulnerability in Git could allow an attacker to place malicious, auto-executing code in a sub-module.
October 10, 2018
Organizations that use Git as a code repository are vulnerable to an attack through submodules and should update their code immediately. The vulnerability, described in CVE-2018-17456, can allow arbitrary code to be executed when a user clones a subdirectory containing malicious code.
The vulnerability - an option-injection attack - is described as quite similar to an earlier vulnerability in a GitHub blog post announcing the issue and its solution. That bug, CVE-2017-1000117, previously had been patched.
The option-injection flaw was reported through the GitHub Bug Bounty program on September 23, with a coordinated disclosure date of October 5.
GitHub Desktop, Atom, the CLI version of Git, and applications that might have embedded Git are all affected by the vulnerability. GitHub Enterprise and GitHub.com are not vulnerable to this flaw, however.
About the Author(s)
Tricks to Boost Your Threat Hunting GameNov 06, 2023
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
Passwords Are Passe: Next Gen Authentication Addresses Today's Threats
How to Deploy Zero Trust for Remote Workforce Security
What Ransomware Groups Look for in Enterprise Victims
Everything You Need to Know About DNS Attacks
How Enterprises Are Managing Application Security Risks in a Heightened Threat Environment