Wind River Support Network

HomeDefectsLIN1021-1365
Fixed

LIN1021-1365 : Security Advisory - git - CVE-2021-40330

Created: Aug 31, 2021    Updated: Sep 25, 2021
Resolved Date: Sep 20, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.6
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

CREATE(Triage):(User=admin) CVE-2021-40330 (https://nvd.nist.gov/vuln/detail/CVE-2021-40330)

CVEs


Live chat
Online