go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.18.0CPE matchmatch criteria | cpe:2.3:a:go-git_project:go-git:*:*:*:*:*:go:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:go-git_project:go-git:6.0.0:alpha1:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.