Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
[jgit-dev] git: malicious repositories can execute remote code while cloning -- is this applicable for JGit?

Hello,

There is a vulnerability in git:
https://www.openwall.com/lists/oss-security/2021/03/09/3
"On case-insensitive filesystems, with support for symbolic links, if Git is configured globally to apply delay-capable clean/smudge filters (such as Git LFS), Git could be fooled into running remote code during a clone."

Is this vulnerability may be used in JGit somehow?
Thank you.


--

                    ISS Art website
Best regards,
Denis Malyshkin, Senior C++ Developer
ISS Art, LLC - custom software development company
Skype: dmalyshkin
Phone: +73812909808

                      Read ISS Art Blog   
                      Find ISS Art on Facebook   
                      Join ISS Art on LinkedIn   
                      Follow ISS Art on Twitter    Visit ISS Art on VK.com
IMPORTANT: The contents of this email and any attachments are confidential and intended for the named recipient(s) only. If you have received this email by mistake, please notify the sender immediately and delete it from your system. You may not copy this email or disclose its contents to anyone. Thank you.

Back to the top