¡¸Îó²îͨ¸æ¡¹GitÐû²¼Æ¾Ö¤Ð¹Â¶Îó²î£¨CVE-2020-5260£©
2020-04-16
¿ËÈÕ£¬GitÐû²¼Ç徲ͨ¸æÐû²¼ÁËÒ»¸ö¿ÉÄÜй¶GitÓû§Æ¾Ö¤µÄÎó²î£¨CVE-2020-5260£©¡£
GitʹÓÃÆ¾Ö¤ÖúÊÖ(credential helper)À´×ÊÖúÓû§´æ´¢ºÍ¼ìË÷ƾ֤¡£¿ÉÊǵ±Ò»¸öURLÖаüÀ¨¾ÓɱàÂëµÄ»»Ðзûʱ£¬¿ÉÄܽ«·ÇÔ¤ÆÚµÄÖµ×¢Èëµ½credential helperµÄÐÒéÁ÷ÖС£Õ⽫ʹ¶ñÒâURLÓÕÆGit¿Í»§¶ËÈ¥Ïò¹¥»÷Õß·¢ËÍÖ÷»úƾ֤¡£µ±Ê¹ÓÃÊÜÓ°Ïì°æ±¾ Git¶Ô¶ñÒâ URL Ö´ÐÐ git clone ÏÂÁîʱ»á´¥·¢¸ÃÎó²î¡£
²Î¿¼Á´½Ó£º
https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q
ÊÜÓ°Ïì°æ±¾
- Git 2.17.x <= 2.17.3
- Git 2.18.x <= 2.18.2
- Git 2.19.x <= 2.19.3
- Git 2.20.x <= 2.20.2
- Git 2.21.x <= 2.21.1
- Git 2.22.x <= 2.22.2
- Git 2.23.x <= 2.23.1
- Git 2.24.x <= 2.24.1
- Git 2.25.x <= 2.25.2
- Git 2.26.x <= 2.26.0
²»ÊÜÓ°Ïì°æ±¾
- Git 2.17.4
- Git 2.18.3
- Git 2.19.4
- Git 2.20.3
- Git 2.21.2
- Git 2.22.3
- Git 2.23.2
- Git 2.24.2
- Git 2.25.3
- Git 2.26.1
½â¾ö¼Æ»®
¹Ù·½ÒÑÐû²¼ÐÞ¸´ÁËÎó²îµÄа汾£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±ÏÂÔØ¸üС£
https://github.com/git/git/releases
ÁíÍ⣬»¹ÌṩÁËÆäËûÒªÁì½â¾ö»ò¹æ±Ü¸ÃÎÊÌ⣺
- ½ûÓÃcredential helper
|
1
2
3
|
git config --unset credential.helper
git config --global --unset credential.helper
git config --system --unset credential.helper
|
- Ìá·À¶ñÒâURL
- git cloneʱ¼ì²éURLµÄÖ÷»úÃûºÍÓû§Ãû²¿·ÖÊÇ·ñ±£´æ±àÂëµÄ»»Ðзû£¨%0a£©»òƾ֤ÐÒé×¢ÈëµÄÖ¤¾Ý£¨ÀýÈçhost=github.com£©
- ×èÖ¹½«×ÓÄ£¿éÓë²»ÊÜÐÅÍеĿÍÕ»Ò»ÆðʹÓ㨲»ÒªÊ¹Óà clone –recurse-submodules£»Ö»ÓÐÔÚ¼ì²é.gitmodulesÖÐÕÒµ½urlÖ®ºó£¬²ÅʹÓÃgit submodule update£©¡£
- ×èÖ¹¶Ô²»ÐÅÍеÄURLÖ´ÐÐ git clone¡£

AG¹«Ë¾ÔÆ







