CVE-2020-5260 is a high-severity vulnerability affecting Git versions prior to April 14th, 2020, including products from Canonical, Debian, Fedora, OpenSUSE, and Git itself. It allows an attacker to trick Git's credential helper into sending private credentials for one legitimate server to a malicious server via specially crafted URLs containing encoded newlines. The attack vector is network-based with low complexity, requiring no user interaction beyond processing a malicious URL, and can lead to a complete compromise of sensitive information (CVSS 7.5). While the vulnerability can be triggered by git clone, it is more likely to occur through automated systems like Git submodules. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17.4CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
>= 2.22.0, < 2.22.3CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
>= 2.18.0, < 2.18.3CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.19.0, < 2.19.4CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* | ||
>= 2.20.0, < 2.20.3CPE matchmatch criteria | cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.